Junglewise Threat Intelligence

CVE-2026-17038: drEryk Gabinet hard-coded API credentials in ticket reporting

CVE-2026-17038 · Severity: info · Published 2026-09-10

Executive brief

drEryk Gabinet is medical practice management software used by clinics and healthcare facilities to manage patient visits, electronic prescriptions, and referrals. The software contains hard-coded API credentials in its ticket reporting component that allow attackers to bypass authentication and directly access the ticket system, enabling unauthorized reading and modification of support tickets and other privileged operations beyond normal application functionality.

Technical details

The vulnerability is a hard-coded credentials issue (CWE-798) in drEryk Gabinet versions before 11.5.0. The ticket reporting component embeds API credentials directly in the application code, which can be extracted and used to authenticate directly to the underlying ticket system API. An attacker with network access to the application or API can discover and reuse these credentials to perform privileged operations such as reading, modifying, or deleting support tickets without proper authorization. The vulnerability requires access to the application or API endpoint but does not require user interaction or legitimate credentials. The issue is fixed in version 11.5.0 and later.

Affected products

  • drEryk Gabinet before 11.5.0

Timeline

  • 2026-09-10: disclosed
  • 2026: patched: Fix available in version 11.5.0

References