CVE-2026-35467
Analyzed
Analyzed - Analysis Complete
Exposure of Stored API Keys via Unprotected Browser Client Storage
Publication date: 2026-04-02
Last updated on: 2026-06-03
Assigner: CERT/CC
Description
Description
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cmu | cveclient | to 1.0.24 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |