Junglewise Threat Intelligence

CVE-2026-75896: TÜBİTAK BİLGEM Liderahenk hard-coded credentials

CVE-2026-75896 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Executive brief

Liderahenk is a centralized management platform used by organizations to administer and monitor endpoint devices. The platform contains hard-coded default credentials that attackers can use to gain unauthorized access to the system, potentially compromising the security of all connected devices and sensitive organizational data.

Technical details

This vulnerability involves the use of hard-coded credentials in Liderahenk, allowing an attacker to authenticate using default usernames and passwords embedded in the application. The vulnerability is accessible over the network without requiring prior authentication or user interaction, making it trivially exploitable. An unauthenticated attacker who discovers or knows the hard-coded credentials can gain full administrative access to the platform, enabling them to compromise all managed endpoints, exfiltrate data, and disrupt operations. The vulnerability affects Liderahenk versions prior to 3.5.5, and patching to the fixed version is the required remediation.

Affected products

  • TÜBİTAK BİLGEM Liderahenk before 3.5.5

Timeline

  • 2026-08-26: disclosed

References