CVE-2016-20026Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-04-07: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-07: 103-1503-1604-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-03-161
Disclosure1
2026-04-071
General1
Full discourse3 posts
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcod... Hardcoded Tomcat manager creds = instant SYSTEM shell via WAR upload - biometric access control systems with root-level... https://zerodaysignal.com/vulnerability/CVE-2016-20026 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet describes CVE‑2016‑20026 as involving hardcoded Tomcat credentials that allow a SYSTEM shell via WAR upload, but it offers no proof‑of‑concept, patch, or evidence of active exploitation.

    0000037
    204 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2016-20026: CRITICAL] ZKTeco ZKBioSecurity 3.0 has hardcoded credentials allowing unauthenticated attackers to access Apache Tomcat server manager app, enabling upload of malicious files for code execut...#cve,CVE-2016-20026,#cybersecurity https://cvefind.com/CVE-2016-20026

    Post summary

    The tweet discloses CVE-2016-20026, describing hardcoded credentials that let attackers upload malicious files to the Tomcat manager, but it lacks PoC details, exploit code, patch info, or evidence of active exploitation.

    0000032
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2016-20026 ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. At… https://www.cve.org/CVERecord?id=CVE-2016-20026

    Post summary

    The entry reports that ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in its embedded Tomcat server, enabling unauthenticated access to the manager application; no PoC, exploit code, or remediation is referenced.

    0000098
    56.7K followersView on X

Explore more