Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Malik Makkes

Researcher fromAbicom Groupe OCI
#18336of 53,633
14.8Total CVSS
Vulnerabilities · 2
High
2
PT-2026-38599
7.3
2026-05-07
Maxhub · Maxhub Pivot · CVE-2026-6411
**Name of the Vulnerable Software and Affected Versions** MAXHUB Pivot client versions prior to 1.36.2 **Description** An issue in the application allows an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Because a hardcoded AES key (Advanced Encryption Standard, a symmetric encryption algorithm) is present within the application, this encrypted data can be decrypted to reveal email addresses and associated information in cleartext. Additionally, an attacker can cause a denial-of-service condition by enrolling multiple unauthorized devices into a tenant via MQTT (Message Queuing Telemetry Transport, a lightweight messaging protocol), which may disrupt tenant operations. **Recommendations** Update to version 1.36.2 or later.
PT-2025-49157
7.5
2025-12-04
Pivot · Pivot · CVE-2025-53704
**Name of the Vulnerable Software and Affected Versions** Pivot client application (affected versions not specified) **Description** The password reset mechanism is weak and could allow an attacker to take over an account. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.