CVE 7.1 HIGH

Use of Hard-Coded Cryptographic Key for Password Storage_CVE-2026-2103

7.1 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

Basic Information

ID CVE-2026-2103
Source BLSOPS
Published Feb 6, 2026 at 16:22
Modified Feb 6, 2026 at 16:39

Affected Product

Vendor Infor
Product SyteLine ERP
Version 10.0.8803.16889
Affected Versions Infor SyteLine ERP 10.0.8803.16889

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.