top of page
perceptive_background_267k.jpg

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code an…

Published:

5 juli 2026 om 22:00:00

Alert date:

6 juli 2026 om 09:01:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access, Database & Storage

An ERP application developed by PROG MIS contains a Use of Hard-coded Credentials vulnerability (CVE-2026-14807). The flaw allows unauthenticated remote attackers to log in to the application without valid credentials. Once logged in, attackers can view application source code and extract database account credentials and passwords. This vulnerability poses a significant risk as it requires no authentication and can be exploited remotely. The exposure of database credentials could lead to further compromise of underlying data systems. The issue was reported via Taiwan CERT (TWCERT) advisories. Hard-coded credentials are a critical security weakness classified under CWE-798. No authentication barrier exists for exploitation, making it immediately actionable for threat actors.

Technical details

Mitigation steps:

Affected products:

PROG MIS ERP App

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page