Home

Description

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra: before 25.3.0.

PUBLISHED Reserved 2026-03-10 | Published 2026-03-13 | Updated 2026-03-13 | Assigner NCSC.ch




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-798 Use of Hard-coded Credentials

Product status

Default status
unaffected

Any version before 25.3.0
affected

Credits

Vicxer Inc. finder

References

support.avantra.com/...tice-Legacy-Built-In-User-Account-rtm vendor-advisory

cve.org (CVE-2026-3873)

nvd.nist.gov (CVE-2026-3873)

Download JSON