CVE-2026-23647Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote access with elevated privileges and may result in full system compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-22: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-18: 1Technical Details · 2026-02-22: 102-1702-1802-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-172
Disclosure2
2026-02-181
Patch1
2026-02-221
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23647 Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying… https://www.cve.org/CVERecord?id=CVE-2026-23647

    Post summary

    The CVE-2026-23647 disclosure notes that Glory RBG-100 recycler systems running ISPK‑08 contain hard‑coded operating system credentials, enabling remote authentication. No PoC, exploit, active exploitation, or patch information is provided.

    00011209
    56.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23647 (CVSS:9.3, CRITICAL) is Awaiting Analysis. Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that..https://nvd.nist.gov/vuln/detail/CVE-2026-23647 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical vulnerability (CVE-2026-23647) in Glory RBG-100 recycler systems, noting hard‑coded OS credentials and a high CVSS score, but provides no PoC, exploit, or patch information.

    0000045
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-23647 exposes hard-coded admin creds in Glory RBG-100 cash recyclers. No patch yet — segment networks & restrict SSH now! European orgs at high risk. https://radar.offseq.com/threat/cve-2026-23647-cwe-798-use-of-hard-coded-credentia-6b5abde7 #OffSeq #vulne... https://t.co/VE7LOoTHaI

    Post summary

    The tweet reports CVE‑2026‑23647, which hard‑codes admin credentials in Glory RBG‑100 cash recyclers, notes no patch is available, and recommends network segmentation and SSH restrictions as mitigations.

    0000033
    265 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23647: Glory RBG-100 Recycler System Ha... Hard-coded creds in Glory RBG-100 recyclers expose SSH to trivial remote root access—classic security malpractice in fi... https://zerodaysignal.com/vulnerability/CVE-2026-23647 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-23647, describing hard‑coded credentials on Glory RBG‑100 recyclers that allow trivial remote root SSH access, but provides no PoC, patch, or exploitation details.

    0000050
    131 followersView on X

Explore more