Description
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the ExposeApiAspect.beforeExposeApi method of dromara orion-visor. A hard‑coded credential is embedded in the source authentication token through remote manipulation. This bypasses the normal login mechanism, enabling unauthenticated access to the application’s API endpoints.

Affected Systems

All instances of dromara orion-visor versions up to and including 2.5.7 are affected. Deployments that have not upgraded beyond these releases expose the ExposeApiAspect feature and therefore carry the hard‑coded credential flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity level. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, suggesting that the vulnerability is unlikely to be widely targeted. However, publicly available exploit code means the issue is operationally demonstrable. The vulnerability is not listed in CISA’s KEV catalog, but the remote nature of the attack vector and the lack of a vendor response increase the urgency for defensive action.

Generated by OpenCVE AI on September 15, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a newer version of dromara orion-visor when one is released and has addressed the flaw.
  • Disable or remove the ExposeApiAspect component to eliminate exposure of the hard‑coded credential.
  • Replace the hard‑coded token with a secure, configurable authentication mechanism (such as an environment variable) in accordance with CWE‑259 and CWE‑798 best practices.

Generated by OpenCVE AI on September 15, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials
First Time appeared Dromara
Dromara orion-visor
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:dromara:orion-visor:*:*:*:*:*:*:*:*
Vendors & Products Dromara
Dromara orion-visor
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dromara Orion-visor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T00:35:31.889Z

Reserved: 2026-09-12T08:58:28.519Z

Link: CVE-2026-90509

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:58.668Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T10:16:56.117

Modified: 2026-09-20T01:16:32.033

Link: CVE-2026-90509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials