CVE Explorer
CVE-2026-26334
Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). These keys are used to encrypt the password of the service account stored in C:\\VeraSMART Data\\app.settings. An attacker with local access to the system can extract the hardcoded keys from the Veramark.Framework.dll module and decrypt the stored credentials. The recovered credentials can then be used to authenticate to the Windows host, potentially
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"VeraSMART","vendor":"Calero","versions":[{"lessThan":"2026 R1","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:18e77c1db71cfbad730def5b0a82ff49b69bfffcc7ee84cb31fa8c71ea93f0d3 · sha256:d16c6f469eefb971… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIG…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:18e77c1db71cfbad730def5b0a82ff49b69bfffcc7ee84cb31fa8c71ea93f0d3 · sha256:d16c6f469eefb971… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-798","description":"CWE-798 Use of Hard-coded Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:18e77c1db71cfbad730def5b0a82ff49b69bfffcc7ee84cb31fa8c71ea93f0d3 · sha256:d16c6f469eefb971… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["product"],"url":"https://www.calero.com/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18e77c1db71cfbad730def5b0a82ff49b69bfffcc7ee84cb31fa8c71ea93f0d3 · sha256:d16c6f469eefb971… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/calero-verasmart-2026-r1-hardcoded-static-aes-keys-allow-decryption-of-service-credentials"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:18e77c1db71cfbad730def5b0a82ff49b69bfffcc7ee84cb31fa8c71ea93f0d3 · sha256:d16c6f469eefb971… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.