


Perceptive Security
SOC/SIEM Consultancy

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code an…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 09:01:53
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Database & Storage
An ERP application developed by PROG MIS contains a Use of Hard-coded Credentials vulnerability (CVE-2026-14807). The flaw allows unauthenticated remote attackers to log in to the application without valid credentials. Once logged in, attackers can view application source code and extract database account credentials and passwords. This vulnerability poses a significant risk as it requires no authentication and can be exploited remotely. The exposure of database credentials could lead to further compromise of underlying data systems. The issue was reported via Taiwan CERT (TWCERT) advisories. Hard-coded credentials are a critical security weakness classified under CWE-798. No authentication barrier exists for exploitation, making it immediately actionable for threat actors.
Technical details
Mitigation steps:
Affected products:
PROG MIS ERP App
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14807
https://www.twcert.org.tw/en/cp-139-11024-c5c1a-2.html
https://www.twcert.org.tw/tw/cp-132-11023-3abe8-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
