CVE-2026-92759

Source
https://cve.org/CVERecord?id=CVE-2026-92759
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92759.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92759
Aliases
  • GHSA-r968-78vw-jj9m
Published
2026-09-16T20:32:26Z
Modified
2026-09-19T03:30:50Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
SecObserve before 1.59.1 Information Disclosure via API Configuration
Details

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92759.json"
}
References

Affected packages

Git / github.com/secobserve/secobserve

Affected ranges

Type
GIT
Repo
https://github.com/secobserve/secobserve
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.17.0"
        },
        {
            "fixed": "1.59.1"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v.*
v.1.47.0
v1.*
v1.17.0
v1.18.0
v1.18.1
v1.19.0
v1.20.0
v1.21.0
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.22.4
v1.22.5
v1.24.0
v1.25.0
v1.26.0
v1.27.0
v1.28.0
v1.28.1
v1.28.2
v1.29.0
v1.29.1
v1.29.2
v1.30.0
v1.30.1
v1.31.0
v1.32.0
v1.32.1
v1.33.0
v1.33.1
v1.34.0
v1.34.1
v1.35.0
v1.36.0
v1.37.0
v1.37.1
v1.38.0
v1.39.0
v1.39.1
v1.39.2
v1.40.0
v1.41.0
v1.41.1
v1.42.0
v1.43.0
v1.43.1
v1.44.0
v1.44.1
v1.45.0
v1.46.0
v1.46.1
v1.47.0
v1.47.1
v1.47.2
v1.47.3
v1.48.0
v1.49.0
v1.50.0
v1.51.0
v1.51.1
v1.52.0
v1.53.0
v1.54.0
v1.55.0
v1.56.0
v1.57.0
v1.58.0
v1.59.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92759.json"