Description
The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.
Published: 2026-10-08
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Compromise of API key leading to unauthorized access to backend services
Action: Immediate Update
AI Analysis

Impact

The Ticket Ryutsu Center Android application stores a hard‑coded credential that can be extracted by an attacker. The credential is used to obtain an API key that the application uses to communicate with its back‑end services. This represents a classic credential compromise (CWE-798) and allows an attacker who learns the key to authenticate to those services as if they were a legitimate app user. The impact includes potential confidentiality and integrity violations of data accessed through the API, and could also enable denial of service if the attacker sends abusive requests.

Affected Systems

The vulnerability is present in the Ticket Ryutsu Center application distributed by Wavedash Co., Ltd. The information given does not specify a version number, so all current releases that have not been patched are considered affected.

Risk and Exploitability

The CVSS score for the issue is 5.1, indicating a medium severity. Because the flaw is derived from hard‑coded credentials inside the application code, an attacker can obtain the necessary data by reverse‑engineering the APK or extracting the binary resources. This requires only local access to the application package on a device or the ability to analyze the released software; no network intrusion is required. The vulnerability is not listed in the CISA KEV catalog, suggesting that known exploit activity is not publicly reported at this time.

Generated by OpenCVE AI on October 8, 2026 at 05:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website or official support channels for a new Ticket Ryutsu Center release that removes the hard‑coded credentials.
  • Install the latest version of Ticket Ryutsu Center that eliminates the credential exposure.
  • If a patch is not yet available, have the vendor revoke the exposed API key and issue a new one that is restricted to authorized application use.
  • Monitor the back‑end services for any unauthorized API activity and reduce key privileges if possible.

Generated by OpenCVE AI on October 8, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Hard‑Coded Credentials in Ticket Ryutsu Center Expose API Key

Thu, 08 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.
Weaknesses CWE-798
References
Metrics cvssV3_0

{'score': 4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-10-08T02:53:50.117Z

Reserved: 2026-09-17T06:02:21.901Z

Link: CVE-2026-92861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.530

Modified: 2026-10-08T03:16:37.530

Link: CVE-2026-92861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:45:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials