Description
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

SecObserve's ApiConfigurationSerializer incorrectly leaks the basic_auth_password field from configuration responses. View-only members can retrieve decrypted passwords used by scanners or integration services via standard REST endpoints. This exposes authentication secrets that could grant attackers access to downstream systems, posing a clear confidentiality risk. The flaw maps to CWE-522.

Affected Systems

All SecObserve installations running versions prior to 1.59.1 are affected, regardless of environment.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not recorded in CISA's KEV catalog. Attackers can exploit it by sending regular API requests to configuration endpoints, which is feasible for any user with view-only product access. No additional credentials or privileges are required beyond the view-only role.

Generated by OpenCVE AI on September 18, 2026 at 06:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SecObserve to version 1.59.1 or later, where the basic_auth_password field is no longer returned.
  • If an upgrade is not immediately possible, deny view-only users access to the API configuration endpoints or remove the exposed field from responses in the current deployment.
  • Periodically rotate integration and scanner credentials and verify that no deprecated secrets remain in the configuration data.

Generated by OpenCVE AI on September 18, 2026 at 06:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Secobserve
Secobserve secobserve
Vendors & Products Secobserve
Secobserve secobserve

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
Title SecObserve before 1.59.1 Information Disclosure via API Configuration
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Secobserve Secobserve
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:25:19.306Z

Reserved: 2026-09-16T19:06:19.779Z

Link: CVE-2026-92759

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:53.179Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:24.470

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:29Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials