CVE-2026-18915: Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
Published Aug 6, 2026
·Updated
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting.
This issue affects eta-otp-lock: before 1.0.4.
Affected Software
1 affected component
eta-otp-lock<1.0.4
Event History
Aug 6, 2026
CVE Published
via MITRE·07:33 AM
Data Sourced
via MITRE·07:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18915?
The severity of CVE-2026-18915 is classified as medium with a score of 5.
2
How do I fix CVE-2026-18915?
To fix CVE-2026-18915, upgrade to eta-otp-lock version 1.0.4 or later.
3
What type of vulnerability is CVE-2026-18915?
CVE-2026-18915 is an exposure of OTP secret through process command-line arguments, leading to potential system footprinting.
4
Which software is affected by CVE-2026-18915?
CVE-2026-18915 affects the eta-otp-lock software developed by TÜBİTAK BİLGEM.
5
When was CVE-2026-18915 published?
CVE-2026-18915 was published on August 6, 2026.