Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.
References
| Link | Resource |
|---|---|
| https://blog.blacklanternsecurity.com/p/cve-2026-2103-infor-syteline-erp | Exploit Third Party Advisory |
Configurations
History
17 Feb 2026, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:infor:syteline_erp:10.0.8803.16889:*:*:*:*:*:*:* | |
| References | () https://blog.blacklanternsecurity.com/p/cve-2026-2103-infor-syteline-erpĀ - Exploit, Third Party Advisory | |
| CWE | CWE-798 | |
| First Time |
Infor syteline Erp
Infor |
06 Feb 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-06 17:16
Updated : 2026-02-17 15:46
NVD link : CVE-2026-2103
Mitre link : CVE-2026-2103
CVE.ORG link : CVE-2026-2103
JSON object : View
Products Affected
infor
- syteline_erp
