The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.
CVSS
No CVSS.
References
Configurations
No configuration.
History
05 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
05 Jun 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-05 11:16
Updated : 2026-06-17 10:13
NVD link : CVE-2026-11347
Mitre link : CVE-2026-11347
CVE.ORG link : CVE-2026-11347
JSON object : View
Products Affected
No product.
