CVE-2026-92759: Secobserve

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

Affected products

  • Secobserve Secobserve: from 1.17.0, before 1.59.1 (fixed in 1.59.1)

Published 2026-09-16. Last modified 2026-09-24.