---
id: CVE-2026-17038
title: "DrEryk Gabinet before 11.5.0\_uses hard-coded API credentials in its ticket reporting component"
summary: "DrEryk Gabinet before 11.5.0\_uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations bey…"
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-798
vendor: drEryk
product: drEryk Gabinet
affected:
  - gabinet < 11.5.0
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:58:20.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17038'
references:
  - url: 'https://cert.pl/posts/2026/09/CVE-2026-17038'
    label: cvd@cert.pl
  - url: 'https://dreryk.pl/produkty/gabinet/'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T12:43:25.258222Z'
cvssSource: cna
ingestedAt: '2026-09-13T04:38:07.399Z'
epss: 0.00264
epssPercentile: 0.16381
---

## Overview

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
