Junglewise Threat Intelligence

CVE-2026-18931: TMT Talassoft Industrial Management Software hard-coded credentials

CVE-2026-18931 · Severity: critical · CVSS 9.1 · Published 2026-09-01

Technologies: TMT Machine Industry and Trade Ltd. Co Talassoft Industrial Management Software. Vendors: TMT Machine Industry and Trade Ltd. Co.

Executive brief

Talassoft Industrial Management Software, used in manufacturing and process control environments, contains hard-coded credentials that attackers can extract from the application. An attacker with access to the software can retrieve sensitive data and potentially gain unauthorized access to critical industrial systems and infrastructure.

Technical details

The vulnerability is a use of hard-coded credentials flaw in Talassoft Industrial Management Software versions 4 through 15. Attackers can extract embedded credentials from the software binaries or configuration files without authentication, allowing unauthorized access to sensitive systems and data. The attack requires local or direct access to the application but does not require user interaction or network traversal. An attacker can leverage these credentials to authenticate to backend systems, access databases, or gain administrative privileges over the industrial management infrastructure. Patches are available in version 16 and later.

Affected products

  • TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software 4 to 15

Timeline

  • 2026-09-01: disclosed

References

Related threats