CVE-2026-17038
Deferred Deferred - Pending Action

Hard-Coded API Credentials in DrEryk Gabinet

Vulnerability report for CVE-2026-17038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: CERT.PL

Description

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dreryk gabinet to 11.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects DrEryk Gabinet software versions before 11.5.0. It involves hard-coded API credentials in the ticket reporting component that allow attackers to authenticate directly to the ticket system API. This enables privileged operations such as reading and modifying existing tickets.

Detection Guidance

Check for hard-coded API credentials in the ticket reporting component of DrEryk Gabinet versions prior to 11.5.0. Inspect configuration files, source code, or network traffic for exposed credentials. Monitor for unauthorized API access attempts or unusual modifications to tickets.

Impact Analysis

An attacker could exploit this to access and modify sensitive ticket data, potentially leading to unauthorized changes, data leaks, or disruption of ticket management operations. This is especially critical if the software handles medical or sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive data, violating confidentiality and integrity requirements under GDPR and HIPAA. Non-compliance may result in legal penalties, reputational damage, and loss of patient trust.

Mitigation Strategies

Update DrEryk Gabinet to version 11.5.0 or later to remove hard-coded credentials. Rotate all API credentials immediately if they may have been exposed. Restrict API access to trusted IPs and implement monitoring for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart