CVE-2026-22906Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 4 mentions (2026-02-09); latest day: 1
  • 10 total mentions across 7 days

Deep dive

Activity timeline10 mentions / 7d
01234Mentions · 2026-02-09: 4Mentions · 2026-02-12: 1Mentions · 2026-02-14: 1Mentions · 2026-02-15: 1Mentions · 2026-02-16: 1Mentions · 2026-03-09: 1Mentions · 2026-03-22: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 4Technical Details · 2026-02-15: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-22: 102-0902-1202-1402-1502-1603-0903-22
Signal classification2 categories
Disclosure
770.0%
General
330.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-094
Disclosure4
2026-02-121
General1
2026-02-141
General1
2026-02-151
General1
2026-02-161
Disclosure1
2026-03-091
Disclosure1
2026-03-221
Disclosure1
Full discourse10 posts
  • elhacker.NET@elhackernet
    General

    [Blog] CVE-2026-22906: Vulnerabilidad Crítica en Almacenamiento de Credenciales https://blog.elhacker.net/2026/02/cve-2026-22906-vulnerabilidad-critica.html

    Post summary

    The snippet merely cites a blog post title and URL about CVE-2026-22906 without providing PoC, exploit, patch, or detailed technical information.

    224183306.1K
    137.7K followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-22906 (CVSS 9.8): Hardcoded AES-ECB key in config decrypts all user creds. Unauth attacker grabs plaintext logins. https://feedly.com/cve/severity/9-10?page=6

    Post summary

    The post announces CVE‑2026‑22906, describing a hardcoded AES‑ECB key that permits unauthenticated attackers to decrypt stored user credentials, marking it as a high‑severity vulnerability.

    0002085
    374 followersView on X
  • Zymeralabs@Zymeralabs
    Disclosure

    CVE-2026-22906 tiene un CVSS de 9.8. El problema: credenciales cifradas con AES en modo ECB y clave hardcodeada. Un atacante remoto sin autenticación puede recuperar contraseñas en texto claro. 🔓

    Post summary

    El mensaje informa sobre un CVE nuevo con alta gravedad (CVSS 9.8), describiendo cómo la clave codificada en AES ECB permite que atacantes remotos recuperen contraseñas en claro, pero no ofrece PoC, herramientas de explotación ni indica explotación activa.

    1000033
    3 followersView on X
  • Antonio Taboada 🇪🇸 hackingyseguridad.com@antonio_taboada
    General

    @elhackernet La vulnerabilidad es sobre la combinacion AES-ECB, CVE-2026-22906 , no asi sobre otras combinaciones AES-

    Post summary

    The tweet references CVE‑2026‑22906, noting it involves the AES‑ECB combination, but offers no further details.

    00010196
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22906 User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover… https://www.cve.org/CVERecord?id=CVE-2026-22906

    Post summary

    The CVE‑2026‑22906 disclosure reveals that user credentials are stored using AES‑ECB with a hardcoded key, allowing unauthenticated remote attackers to decrypt configuration files and recover credentials.

    00010206
    56.5K followersView on X
  • fernand0@fernand0
    Disclosure

    CVE-2026-22906: Vulnerabilidad Crítica en Almacenamiento de Credenciales - Una Al Día https://unaaldia.hispasec.com/2026/02/cve-2026-22906-vulnerabilidad-critica-en-almacenamiento-de-credenciales.html

    Post summary

    The text announces a new critical credential‑storage vulnerability (CVE-2026-22906) without providing proof‑of‑concept, exploit details, or patch information, indicating a preliminary disclosure.

    0000059
    6.1K followersView on X
  • Manuel Marcos@manolomarcosp
    General

    CVE-2026-22906: Vulnerabilidad Crítica en Almacenamiento de Credenciales https://unaaldia.hispasec.com/2026/02/cve-2026-22906-vulnerabilidad-critica-en-almacenamiento-de-credenciales.html

    Post summary

    The post announces CVE‑2026‑22906 as a critical credential storage vulnerability but provides no further technical, exploit, or remediation details.

    0000036
    224 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22906: CRITICAL] User credentials stored insecurely in a configuration file using AES-ECB encryption with a hardcoded key present a serious cybersecurity risk, allowing remote attackers to decrypt ...#cve,CVE-2026-22906,#cybersecurity https://cvefind.com/CVE-2026-22906

    Post summary

    A critical vulnerability (CVE-2026-22906) is disclosed, describing credentials stored insecurely in a config file encrypted with AES-ECB using a hardcoded key, enabling remote attackers to decrypt the credentials.

    0000078
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-22906 in WAGO 0852-1322 exposes credentials via hardcoded AES key! No patch yet — restrict config access & monitor closely. EU industrial orgs at high risk. https://radar.offseq.com/threat/cve-2026-22906-cwe-321-use-of-hard-coded-cryptogra-e9045210 #OffSeq... https://t.co/Pwk14ZTgzn

    Post summary

    CVE-2026-22906 has been disclosed, affecting WAGO 0852-1322 by exposing credentials through a hardcoded AES key; no patch is available yet, so administrators should restrict config access and monitor for exploitation.

    0000040
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22906 - Critical User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext username... https://www.thehackerwire.com/vulnerability/CVE-2026-22906/ https://t.co/mDDE7pxF7Z

    Post summary

    The text discloses a critical vulnerability (CVE‑2026‑22906) involving AES‑ECB with a hardcoded key that lets remote attackers recover plaintext usernames from configuration files; no patch, PoC, or active exploitation is reported.

    0000080
    112 followersView on X

Explore more