Mehrere Schwachstellen (CVE-2026-50110, CVE-2026-56413, CVE-2026-56415, CVE-2026-7839, CVE-2026-7840) in Storage
Stonefly - Storage Concentrator - CRITICAL - CVE-2026-50110.
The Storage Concentrator product line by Stonefly is susceptible to a vulnerability that involves hardcoded credentials for various internal services embedded within its configuration file. Although these credentials are encoded, the encoding can be easily reversed to obtain plaintext. As a result, malicious actors could gain unauthorized access to a significant number of interconnected systems, including database accounts, licensing management, replication services, and third-party integrations. This widespread vulnerability poses a considerable risk to the security and integrity of organizational data and processes.
Quelle: securityvulnerability.io