Description
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Remote Access
Action: Apply Patch
AI Analysis

Impact

The flaw in Lenve VHR 1.0‑SNAPSHOT allows an attacker to modify the vhr.sql file to bypass authentication and use default credentials. Based on the description, it is inferred that this can allow unauthenticated remote access. The weakness involves incorrect credential handling as identified by CWE‑1392.

Affected Systems

The affected product is Lenve V‑SNAPSHOT build. No additional version details are provided beyond the snapshot identifier. Users operating this version should verify that they are not using the default configuration or that any exposed interfaces that modify SQL files are secured.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The EPSS score is < 1%, suggesting a very low but non‑zero likelihood that this vulnerability will be exploited. Publicly available exploits exist, based on the description it is inferred that an attacker with access to the application or its web interface could manipulate vhr.sql and log in with default credentials. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 17:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Lenve VHR release that removes the default credential usage.
  • Immediately change any remaining default usernames and passwords in the application configuration.
  • Disable or secure any feature that allows direct modification of SQL files or scripts exposed to the network.

Generated by OpenCVE AI on September 15, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title lenve vhr vhr.sql default credentials
First Time appeared Lenve
Lenve vhr
Weaknesses CWE-1392
CPEs cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*
Vendors & Products Lenve
Lenve vhr
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:00:46.945Z

Reserved: 2026-09-12T08:23:58.593Z

Link: CVE-2026-90498

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:38.613Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T07:17:41.533

Modified: 2026-09-15T15:17:27.507

Link: CVE-2026-90498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses