CVE-2026-92861
Received Received - Intake

Hard-Coded API Key in Ticket Ryutsu Center App

Vulnerability report for CVE-2026-92861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: JPCERT/CC

Description

The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Wavedash Co., Ltd. Ticket Ryutsu Center 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Android application 'Ticket Ryutsu Center' contains hard-coded credentials, specifically an API key embedded in the app code. This allows an attacker to extract the key and potentially misuse it for unauthorized access or other malicious activities.

Detection Guidance

To detect hard-coded credentials in the Ticket Ryutsu Center app, inspect the app's APK file using tools like apktool or jadx to search for API keys or credentials in the code. Use grep commands such as grep -r 'api_key' or grep -r 'hardcoded' on decompiled files. Check for known default credentials or strings in the app's resources or manifest.

Impact Analysis

An attacker could retrieve the hard-coded API key and use it to impersonate the application, display malicious websites within the app, or trick users into phishing attacks by sending malicious intents to the vulnerable app.

Compliance Impact

The hard-coded credentials vulnerability (CVE-2026-92861) in the Ticket Ryutsu Center app could lead to unauthorized access to user data, potentially violating GDPR and HIPAA requirements for data protection and confidentiality. Exposure of API keys may enable attackers to intercept sensitive information, undermining compliance with these regulations.

Mitigation Strategies

Update the Ticket Ryutsu Center application to version 4.2.0 or later to remove the hard-coded API key and address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92861. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart