Back to overview

CVE-2025-10560

CRITICAL
9.3
CVSS 4.0
Description
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authenticated as the AWS account root identity and provided access to Worksnaps production cloud resources, including S3 buckets containing sensitive data such as screenshots of user desktops. An attacker with access to the affected client binaries could extract or recover the credentials and use them to access affected Worksnaps cloud resources.

Metadata

CVE ID
CVE-2025-10560
State
PUBLISHED
Assigner
SEC-VLab
Reserved
2025-09-16 13:21 UTC
Published
2026-06-18 08:32 UTC
Last updated
2026-06-21 07:37 UTC
Primary CWE
CWE-798
CWE-798 Use of Hard-coded Credentials
Vendor / Product
Silver Leaf Technologies, Inc. / Worksnaps.net Worksnaps
Sources
cve.org  ·  NVD

Severity & Metrics

9.3 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Silver Leaf Technologies, Inc. Worksnaps.net Worksnaps Worksnaps before 1.6.20260201
Weakness (CWE)
CWESourceDescription
CWE-798 cna CWE-798 Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Back to overview