Junglewise Threat Intelligence

CVE-2026-92759: SecObserve information disclosure in API configuration

CVE-2026-92759 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

SecObserve is an open source vulnerability and license management system used by development teams to track security issues across software projects. The vulnerability allows view-only members of a product to retrieve sensitive decrypted passwords for scanner and integration service accounts through the REST API, potentially exposing credentials used to authenticate with external security tools and services.

Technical details

An information disclosure vulnerability exists in the ApiConfigurationSerializer component of SecObserve versions before 1.59.1, where the basic_auth_password field is not properly stripped from API configuration responses. Users with view-only product membership can call standard REST endpoints to retrieve the decrypted basic-auth passwords associated with configured scanner or integration service accounts. The vulnerability requires authentication and product membership but no additional privilege escalation. This allows attackers with read-only access to expose credentials used for downstream integrations.

Affected products

  • SecObserve SecObserve before 1.59.1

Timeline

  • 2026-09-16: disclosed

References