Description
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key
. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data confidentiality breach through decryption of stored SSH private keys and host passwords
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the HostKeyServiceImpl.encryptKey method of dromara orion‑visor, where a hard‑coded AES key is used for encryption. An attacker can exploit this weakness to decrypt SSH private keys and host passwords stored by the system, thus compromising the confidentiality of credentials. The flaw corresponds to the CWE‑320 and CWE‑321 classes of cryptographic practice issues.

Affected Systems

All installations of dromara orion‑visor up to version 2.5.7 are affected. The vulnerable component is orion‑visor‑modules/orion‑visor-module-asset/orion‑visor‑module-asset‑service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is below 1%, pointing to a very low probability of exploitation, yet the vulnerability is already publicly disclosed and usable. The product has not released a patch at the time of analysis, so the vulnerability remains unmitigated. While the vulnerability is not listed in CISA KEV, that does not diminish the potential impact. Service operators using affected versions should consider that the possibility of credential compromise remains real and should plan remediation promptly.

Generated by OpenCVE AI on September 15, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest version of dromara orion‑visor that removes the hard‑coded key.
  • Restrict external network access to the Orion‑Visor management interface to trusted IPs or internal networks only.
  • If an upgrade is not feasible, modify the source code to replace the hard‑coded encryption key with a configurable key, rebuild, and redeploy the patched application.

Generated by OpenCVE AI on September 15, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key
First Time appeared Dromara
Dromara orion-visor
Weaknesses CWE-320
CWE-321
CPEs cpe:2.3:a:dromara:orion-visor:*:*:*:*:*:*:*:*
Vendors & Products Dromara
Dromara orion-visor
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Dromara Orion-visor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:46:06.696Z

Reserved: 2026-09-12T08:58:31.850Z

Link: CVE-2026-90510

cve-icon Vulnrichment

Updated: 2026-09-14T17:45:53.382Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:16:59.827

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses