Junglewise Threat Intelligence

CVE-2026-50110: StoneFly Storage Concentrator hardcoded credentials in configuration file

CVE-2026-50110 · Severity: critical · CVSS 9.2 · Published 2026-06-30

Technologies: StoneFly Storage Concentrator, StoneFly Storage Concentrator Virtual Machine. Vendors: StoneFly.

Executive brief

StoneFly Storage Concentrator, a solution used for managing enterprise data storage and virtualization, contains hardcoded credentials within its configuration files. An attacker with access to the system can recover these credentials to gain unauthorized access to internal databases, licensing systems, and replication services. This could lead to significant data exposure or the compromise of multiple interconnected business systems.

Technical details

The StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) utilize a configuration file containing hardcoded credentials for various internal services (CWE-798). Although these credentials are stored in an encoded format, the encoding is reversible, allowing an attacker with local access to obtain plaintext passwords. The affected credentials provide access to database accounts, licensing services, replication services, and third-party integrations. Successful exploitation allows for broad unauthorized access across interconnected systems. The vulnerability is addressed in version 8.0.4.29.

Affected products

  • StoneFly Storage Concentrator < 8.0.4.26
  • StoneFly Storage Concentrator Virtual Machine < 8.0.4.26

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats