Home

Description

Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 hashes that are inadequately obfuscated using a simple Caesar cipher, which can be easily reversed to recover the original hash values and access the protected data.

PUBLISHED Reserved 2026-05-18 | Published 2026-06-03 | Updated 2026-06-04 | Assigner certcc

Problem types

CWE-922 Insecure Storage of Sensitive Information

Product status

Any version
affected

References

kb.cert.org/vuls/id/595768

cve.org (CVE-2026-8878)

nvd.nist.gov (CVE-2026-8878)

Download JSON