Junglewise Threat Intelligence

CVE-2026-11347: linqi hardcoded cryptographic keys and weak IV generation

CVE-2026-11347 · Severity: info · CVSS 8.5 · Published 2026-06-05

Technologies: Linqi. Vendors: Linqi.

Executive brief

The linqi application contains security flaws related to how it encrypts sensitive information. An attacker with local access to the system can bypass these protections to recover database credentials and other sensitive configuration details. This could lead to unauthorized access to corporate databases and a total compromise of the application's data integrity.

Technical details

The linqi application is vulnerable to two primary cryptographic weaknesses: the use of hardcoded cryptographic keys (CWE-321) and a cryptographically weak PRNG for Initialization Vector (IV) generation (CWE-338). Specifically, the application uses a limited ASCII charset and a weak algorithm to generate IVs for AES/CBC encryption. These flaws make known-plaintext attacks feasible. An attacker with local access and low privileges can exploit these vulnerabilities to decrypt obfuscated strings within configuration files, such as 'appsettings.json', potentially revealing plaintext database credentials and other sensitive ConnectionString values.

Affected products

  • linqi linqi

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats