← Back

CVE-2026-35467

nvd nist
Published: Apr 2, 2026Modified: Jun 3, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Affected (1)

Products: Cmu: Cveclient
1 product
Cveclient
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.24

References (2)

Source: cret@cert.org
Product
Source: cret@cert.org
Issue TrackingPatch

Timeline

No history available yet.