Security Advisory

CVE-2026-42518

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-29 08:37:32
Last updated 2026-04-29 12:02:59
Assigner CERT-In
CVSS score 8.7
State PUBLISHED

Description

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys. Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.