Executive brief
VOCALOID6 Editor is a music production software used to create synthetic vocals for compositions. An attacker can exploit hard-coded credentials embedded in the application to impersonate legitimate users and gain unauthorized access to Yamaha's activation and content servers, potentially enabling unauthorized downloads, account takeover, or service abuse.
Technical details
The vulnerability is a hard-coded credentials issue (CWE-798) in VOCALOID6 Editor versions 6.13.0 and earlier. An attacker with network access can exploit embedded credentials to impersonate the VOCALOID6 Editor and authenticate to Yamaha's activation and content servers without valid user credentials. The vulnerability requires no authentication or user interaction and allows information disclosure (confidentiality impact). The vendor released VOCALOID6 Editor version 6.13.3 on September 16, 2026, which is presumed to address this vulnerability.
Affected products
- Yamaha VOCALOID6 Editor 6.13.0 and earlier
Timeline
- 2026-08-21: disclosed
- 2026-09-16: patched: VOCALOID6 Editor version 6.13.3 released