ZeroHour

CVE-2026-92759

niche

Basic-auth password disclosure in SecObserve API configuration responses

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

SecObserve, an open-source vulnerability management platform, fails to strip the basic_auth_password field from API configuration responses in its ApiConfigurationSerializer. Any product member with view-only permissions can therefore call standard REST endpoints and retrieve the decrypted basic-auth password of configured scanner or integration service accounts. An attacker holding a low-privileged account gains working credentials for the connected scanner or integration services, which can enable further access to those upstream systems. All SecObserve deployments running versions before 1.59.1 are affected. No public proof-of-concept or exploitation has been reported, and the issue is not in CISA's KEV catalog.

What to do: Upgrade SecObserve to version 1.59.1 or later. Rotate the basic-auth credentials of all scanner and integration service accounts configured in SecObserve, since any view-only member may have already been able to read them via the REST API. Review product member roles and confirm low-privileged users only have the access they need.

Affected
SecObserve (open-source project) SecObserveall versions before 1.59.1
Estimated exposure
nichelikely hundreds to low thousands of self-hosted instances worldwide — SecObserve is a niche open-source vulnerability management tool that organizations self-host (typically in Docker), so exposure is limited by its modest open-source adoption and by the fact that most instances sit behind authentication…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.