CVE-2026-49204
Leftover Debug Modules with Hard-Coded AWS Cognito Credentials
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: 8fc372e3-d9c5-46e4-9410-38469745c639
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves leftover debug modules that contain fixed credentials used for internal AWS Cognito test sandboxes. These hardcoded credentials can be discovered and exploited by attackers, potentially allowing unauthorized access to internal assets.
How can this vulnerability impact me? :
The presence of fixed credentials in leftover debug modules can lead to unauthorized access to internal AWS Cognito test environments. This can result in asset exploitation, including unauthorized data access or manipulation, which may compromise the security and integrity of your systems.