CVE-2026-17038: Use of Hard-coded Credentials in drEryk Gabinet
Published Sep 10, 2026
·Updated
DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.
Affected Software
1 affected component
drEryk Gabinet<11.5.0
Event History
Sep 10, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
DrEryk Gabinet versions before 11.5.0 are affected. The exposed credentials are used by the ticket reporting component.
2
What access can an attacker gain with the embedded credentials?
The credentials can authenticate directly to the ticket system API. An attacker could perform privileged operations outside the application's normal interface, including reading and modifying tickets.