CVE-2026-5128Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to retrieve highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. In addition, application logs expose authentication artifacts such as access tokens, refresh tokens, and session identifiers. This information allows an attacker to generate valid Steam Guard (2FA) codes, hijack authenticated sessions, and obtain full control over the affected Steam account, including unauthorized access to inventory and trading functionality. No fix is available because the repository is archived and no longer maintained.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCWE-532: Insertion of Sensitive Information into Log File

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-30); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-03-30: 4Mentions · 2026-03-31: 2Technical Details · 2026-03-30: 4Technical Details · 2026-03-31: 103-3003-31
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-304
Disclosure4
2026-03-312
Disclosure2
Full discourse6 posts
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-5128 | CVSS 10.0 🔴 CVE-2026-3300 | CVSS 9.8 🔴 CVE-2026-32714 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑severity CVEs with their CVSS scores and links to a vulnerabilities page, but it provides no PoCs, exploit code, patches, or evidence of active exploitation.

    0001037
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5128 A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to… https://www.cve.org/CVERecord?id=CVE-2026-5128

    Post summary

    The text announces a sensitive information exposure vulnerability (CVE‑2026‑5128) in ArthurFiorette steam‑trader 2.1.1 that allows unauthenticated requests to the /users API endpoint; no exploit, patch, or PoC details are provided.

    0001098
    56.8K followersView on X
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-5128: Steam Trader 2.1.1 Unauthenticated Sensitive Data Exposure https://labs.cosmicbytez.ca/security/cve-2026-5128 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The post announces CVE-2026-5128 affecting Steam Trader 2.1.1 and provides a link to an external advisory, with no evidence of PoC, exploit code, active exploitation, or mitigation details.

    0000043
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-5128 - Critical A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to retrieve highly se... https://www.thehackerwire.com/vulnerability/CVE-2026-5128/ https://t.co/KDBjPlPgm1

    Post summary

    The post announces a critical information disclosure flaw in ArthurFiorette steam-trader 2.1.1, allowing unauthenticated users to retrieve sensitive data through the /users endpoint, with no mention of exploits, patches, or active attacks.

    0000052
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5128: CRITICAL] ⚠️ Critical vulnerability in ArthurFiorette steam-trader 2.1.1 allows attackers to access sensitive data like Steam account details, risking account hijacking and unauthorized access....#cve,CVE-2026-5128,#cybersecurity https://cvefind.com/CVE-2026-5128

    Post summary

    The post alerts about CVE-2026-5128, a critical flaw in ArthurFiorette steam‑trader 2.10.1 that permits access to Steam account information, but offers no evidence of exploitation, PoC, or patches.

    0000047
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5128: ArthurFiorette (CVSS: 10.0)... Plaintext Steam credentials + 2FA secrets exposed via unauthenticated `/users` endpoint = instant account takeover with ... https://zerodaysignal.com/vulnerability/CVE-2026-5128 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-5128, indicating that Steam credentials and 2FA secrets are exposed through an unauthenticated `/users` endpoint, enabling instant account takeover, but it provides no patch, PoC, or active‑exploit indication.

    0000072
    194 followersView on X

Explore more