CVE-2026-92759
nicheBasic-auth password disclosure in SecObserve API configuration responses
SecObserve, an open-source vulnerability management platform, fails to strip the basic_auth_password field from API configuration responses in its ApiConfigurationSerializer. Any product member with view-only permissions can therefore call standard REST endpoints and retrieve the decrypted basic-auth password of configured scanner or integration service accounts. An attacker holding a low-privileged account gains working credentials for the connected scanner or integration services, which can enable further access to those upstream systems. All SecObserve deployments running versions before 1.59.1 are affected. No public proof-of-concept or exploitation has been reported, and the issue is not in CISA's KEV catalog.
What to do: Upgrade SecObserve to version 1.59.1 or later. Rotate the basic-auth credentials of all scanner and integration service accounts configured in SecObserve, since any view-only member may have already been able to read them via the REST API. Review product member roles and confirm low-privileged users only have the access they need.
| SecObserve (open-source project) SecObserve | all versions before 1.59.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.