CVE-2026-92759: SecObserve before 1.59.1 Information Disclosure via API Configuration

Published Sep 16, 2026
·
Updated

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basicauthpassword field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

Affected Software

1 affected component
SecObserve<1.59.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SecObserve to a version that resolves this vulnerability.

    Fixed in 1.59.1
  2. Compensating control

    Restrict access to SecObserve REST endpoints so view-only product members cannot retrieve decrypted basic-auth passwords returned by ApiConfigurationSerializer (e.g., limit API access/roles to authorized administrators only).

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can retrieve the exposed credentials?

View-only product members can retrieve decrypted basic-auth passwords for configured scanner or integration service accounts through standard REST endpoints. Exploitation requires network access and low-privileged authenticated access; no user interaction is required.

2

Which deployments are affected?

SecObserve versions before 1.59.1 are affected. The issue applies where API configurations contain a basic_auth_password value for a scanner or integration service account.

3

How can I determine whether credentials may have been exposed?

Review whether view-only members had access to the affected REST endpoints and whether API configurations included basic-auth passwords. Because the password is returned decrypted in API configuration responses, treat configured service-account passwords as potentially disclosed to those members.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203