CVE-2026-18931

9.1

TMT Machine Industry and Trade Ltd. · Talassoft Industrial Management Software

Talassoft Industrial Management Software contains a hard-coded credentials vulnerability that allows unauthenticated attackers to retrieve sensitive system data.

Executive summary

A critical hard-coded credentials vulnerability in Talassoft Industrial Management Software allows unauthenticated remote attackers to bypass security and access sensitive data.

Vulnerability

The software contains hard-coded credentials that enable an unauthenticated attacker to gain unauthorized access to sensitive information. This vulnerability stems from the use of static, embedded authentication tokens that cannot be rotated or removed by the end user.

Business impact

The presence of hard-coded credentials poses a severe risk to organizational confidentiality and integrity. With a CVSS score of 9.1, this flaw allows unauthorized actors to extract sensitive industrial management data, potentially leading to operational disruption, loss of intellectual property, or regulatory compliance failures.

Remediation

Immediate Action: Upgrade Talassoft Industrial Management Software to version 16 or later immediately to remove the hard-coded credentials.

Proactive Monitoring: Review system access logs for any unauthorized authentication attempts or patterns indicative of automated credential harvesting.

Compensating Controls: Deploy a Web Application Firewall (WAF) or network access control list to restrict access to the management interface to known, trusted IP addresses until the software update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a critical security failure that must be addressed with the highest priority. Organizations using affected versions of Talassoft Industrial Management Software should prioritize the transition to version 16 or higher to permanently remediate the presence of hard-coded credentials and secure the environment against unauthorized access.

Sources

Originally found and disclosed by Efe Özel, with Cemil Sefa Özcan (analyst), FORDEFENCE (sponsor), per the CVE Program record.