CVE-2026-35467
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
02/04/2026
Last modified:
03/04/2026
Description
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



