THREATOPS
THREAT OPSThreat News › [NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records

[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records

lowfulldisclosurePublished 2026-08-26

<p>Posted by advisories on Aug 26</p>----------------------------------------------------------------------------<br /> NotCVE Advisory — NotCVE-2026-0012<br /> ----------------------------------------------------------------------------<br /> <br /> [-] Summary:<br /> kamalpanse18 EmpManageX, a Flask-based employee management application,<br /> ships hard-coded administrative credentials in its a

MITRE ATT&CK techniques

Original source: https://seclists.org/fulldisclosure/2026/Aug/113