CVE-2026-18931: Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software
Published Sep 1, 2026
·Updated
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data.
This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
Affected Software
1 affected component
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software<16
Event History
Sep 1, 2026
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Talassoft Industrial Management Software versions from V.4 before V.16 are affected. The provided information does not identify any configuration prerequisite.
2
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates that the vulnerability is network-accessible, requires low attack complexity, needs no privileges, and requires no user interaction.
3
What could an attacker gain through exploitation?
The vulnerability allows retrieval of embedded sensitive data. The CVSS vector rates confidentiality and integrity impact as high, with no availability impact indicated.