Back to overview

CVE-2026-16581

MEDIUM
5.3
CVSS 3.1
Description
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

Metadata

CVE ID
CVE-2026-16581
State
PUBLISHED
Assigner
icscert
Reserved
2026-07-22 13:40 UTC
Published
2026-07-28 20:05 UTC
Last updated
2026-07-28 20:05 UTC
Primary CWE
CWE-540
CWE-540 Inclusion of sensitive information in source code
Vendor / Product
igloohome / Smart Lock Mobile Application
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
igloohome Smart Lock Mobile Application Version 3.2.3
Weakness (CWE)
CWESourceDescription
CWE-540 cna CWE-540 Inclusion of sensitive information in source code
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Back to overview