Article
Cyber News / Article / Vulnerability in drEryk Gabinet software

CE
CERT Polska-about 20 hours ago
Vulnerability in drEryk Gabinet software
CERT Polska has received a report about vulnerability in drEryk Gabinet software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-17038: DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.
We thank Wojciech GieÅda for the responsible vulnerability report.
Related articles
Io
Ionut ArghireCritical NetScaler Vulnerability Exploited in Attacks
about 18 hours ago
Ab
AbinayaCISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
about 17 hours ago
An
Anne Aarness - Chris PrallCrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
9 days ago
You might Also like
Gu
Guru Baran-about 4 hours ago
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

Bi
Bill Toulas-about 9 hours ago
New Android malware encrypts files, steals data, and harasses victims

La
Lawrence Abrams-about 10 hours ago
