Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-42518

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321 Uso de claves de cifrado embebidas en el software
Fecha de publicación:
29/04/2026
Última modificación:
29/04/2026

Descripción

*** Pendiente de traducción *** This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys.<br /> <br /> Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.