


Perceptive Security
SOC/SIEM Consultancy

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Pas…
Published:
26 augustus 2026 om 00:00:00
Alert date:
26 augustus 2026 om 19:06:19
Source:
nvd.nist.gov
Identity & Access, Enterprise Applications
A Use of Hard-coded Credentials vulnerability has been identified in TÜBİTAK BİLGEM Software Technologies Research Institute's Liderahenk software. The vulnerability allows attackers to attempt authentication using common or default usernames and passwords embedded in the application. All versions of Liderahenk prior to 3.5.5 are affected. The vulnerability is classified under CWE for hard-coded credentials and enables a well-known attack vector of trying default credentials. Users are advised to upgrade to version 3.5.5 or later to remediate the issue. The vulnerability was reported via the Turkish national cybersecurity advisory portal. Hard-coded credentials represent a significant security risk as they cannot be changed by end users and may provide persistent unauthorized access if discovered.
Technical details
Mitigation steps:
Affected products:
Liderahenk (before 3.5.5)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-75896
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0916
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
