Article

    Cyber News / Article / Vulnerability in drEryk Gabinet software

    Vulnerability in drEryk Gabinet software
    CE
    CERT Polska-about 20 hours ago

    Vulnerability in drEryk Gabinet software

    CERT Polska has received a report about vulnerability in drEryk Gabinet software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-17038: DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.

    We thank Wojciech Giełda for the responsible vulnerability report.

    Original source