
Critical Vulnerability in User Credential Storage
General
The vulnerability CVE-2026-22906 (CVSS score 9.8/10) affects products that store user credentials using AES encryption in ECB mode with a hardcoded key. This encryption method allows a remote attacker, without prior authentication, to retrieve usernames and passwords in plaintext. No details about the affected products or the disclosure date are provided. The impact includes the complete exposure of stored credentials.