SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-41874

MEDIUM · CVSS 6.8 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Quick.Cart versions, particularly 6.7, contain hard-coded, plaintext admin credentials stored in a configuration file, exposing them to potential retrieval by attackers with server file system access. This vulnerability could lead to privilege escalation, making it critical for administrators and security teams managing Quick.Cart installations to assess their exposure and implement appropriate security measures. Despite the vendor's assessment of a very low likelihood of exploitation, organizations should prioritize addressing this issue to safeguard against unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41874
Severity
MEDIUM
CVSS
6.8
EPSS
0.13%

Original NVD Description

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.