CVE-2026-105147

Published: Ott 04, 2026 Last Modified: Ott 04, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
HIGH 7,5
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

259

Use of Hard-coded Password

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity Hide Activities Reduce Maintainability
Applicable Platforms
Technologies: ICS/OT
View CWE Details
798

Use of Hard-coded Credentials

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Other
Potential Impacts:
Bypass Protection Mechanism Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Other
Applicable Platforms
Technologies: Mobile, ICS/OT
View CWE Details
https://gist.github.com/DReazer/6bc4f88053ec35f8358395bcc0d1a0bb
https://vuldb.com/cve/CVE-2026-105147
https://vuldb.com/submit/947748
https://vuldb.com/vuln/413372
https://vuldb.com/vuln/413372/cti