Loading vulnerability details…
CVSS v3.1
N/A
CVSS v4.0
6.3
EPSS
0.32%
Published
May 14, 2026
Modified
May 14, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensitive keys, potentially leading to loss of confidentiality.
Weaknesses (CWE)