Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. This allows an attacker with local access to recover any encrypted password to plaintext using a single SHA-1 hash and RC4 decryption operation, with no brute force required.
References
Configurations
No configuration.
History
29 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://github.com/user6400/cve-2026-39031-lansweeper-lsrunase2-lsencrypt2 - | |
| References | () https://usermode.net/cve/lansweeper_lsrunase2_lsencrypt2_cve.pdf - | |
| CWE | CWE-321 |
26 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 21:16
Updated : 2026-06-29 19:27
NVD link : CVE-2026-39031
Mitre link : CVE-2026-39031
CVE.ORG link : CVE-2026-39031
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key
