CVE-2026-92759: Secobserve
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
Affected products
- Secobserve Secobserve: from 1.17.0, before 1.59.1 (fixed in 1.59.1)
Published 2026-09-16. Last modified 2026-09-24.