An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials. | |
| Title | MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint | |
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-04-02T09:00:17.434Z
Reserved: 2026-03-23T13:15:49.382Z
Link: CVE-2026-33617
No data.
Status : Received
Published: 2026-04-02T10:16:17.260
Modified: 2026-04-02T10:16:17.260
Link: CVE-2026-33617
No data.
OpenCVE Enrichment
No data.
Weaknesses