CVE-2026-33617
Received
Received - Intake
Unauthorized Remote Access to Database Credentials via Config File Exposure
Publication date: 2026-04-02
Last updated on: 2026-04-16
Assigner: CERT VDE
Description
Description
An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mbconnectline | mbconnect24 | to 2.19.4 (inc) |
| mbconnectline | mymbconnect24 | to 2.19.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-497 | The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. |