CVE-2026-90510
CVE-2026-90510 is a high-severity vulnerability with a CVSS 3.x base score of 8.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-320.
Key facts
- Severity: High (CVSS 3.x base score 8.3)
- CVSS v2: 7.5
- CVSS v4: 5.5
- EPSS exploit prediction: 0% (22nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-320
- Published:
- Last modified:
Description
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Frequently asked questions
- What is CVE-2026-90510?
- A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
- How severe is CVE-2026-90510?
- CVE-2026-90510 has a CVSS 3.x base score of 8.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-90510 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (22nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-90510?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-90510 published?
- CVE-2026-90510 was published on 2026-09-13 and last updated on 2026-09-14.
References
- https://github.com/dromara/orion-visor/
- https://github.com/dromara/orion-visor/issues/171
- https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/Hardcoded%20AES%20Encryption%20Key%20Enables%20Decryption%20of%20SSH%20Private%20Keys%20and%20Host%20Passwords%20(CWE-321)_en.md
- https://vuldb.com/cve/CVE-2026-90510
- https://vuldb.com/submit/911865
- https://vuldb.com/vuln/403098
- https://vuldb.com/vuln/403098/cti
Other CWE-320 vulnerabilities
- CVE-2016-10467 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD…
- CVE-2016-10421 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206,…
- CVE-2018-0124 — Critical (CVSS 9.8): A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to…
- CVE-2015-0936 — Critical (CVSS 9.8): Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows…
- CVE-2015-4166 — Critical (CVSS 9.8): Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have…
- CVE-2024-36391 — Critical (CVSS 9.1): MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic