CVE Explorer
CVE-2026-6411
This vulnerability, in the MAXHUB Pivot client application versions
prior to v1.36.2, may allow an attacker to obtain encrypted tenant email
addresses and related metadata from any tenant. Due to the presence of a
hardcoded AES key within the application, the encrypted data can be
decrypted, enabling access to tenant email addresses and associated
information in cleartext. Furthermore, an attacker may be able to cause a
denial-of-service condition by enrolling multiple unauthorized devices
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"MAXHUB Pivot client application","vendor":"MAXHUB","versions":[{"lessThan":"1.36.2","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"1.36.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-327","description":"CWE-327","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-127-01.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/references/2
{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-127-01"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/references/1
{"url":"https://www.maxhub.com/en/support/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9e2cc5a3f6f724291e66dfe0797646439c39d35258749ea410fd55dc7984c553 · sha256:a9a9ce99b3802c94… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.