PT-2026-38599 · Maxhub · Maxhub Pivot
Malik Makkes
+1
·
Published
2026-05-07
·
Updated
2026-05-10
·
CVE-2026-6411
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MAXHUB Pivot client versions prior to 1.36.2
Description
An issue in the application allows an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Because a hardcoded AES key (Advanced Encryption Standard, a symmetric encryption algorithm) is present within the application, this encrypted data can be decrypted to reveal email addresses and associated information in cleartext. Additionally, an attacker can cause a denial-of-service condition by enrolling multiple unauthorized devices into a tenant via MQTT (Message Queuing Telemetry Transport, a lightweight messaging protocol), which may disrupt tenant operations.
Recommendations
Update to version 1.36.2 or later.
Fix
DoS
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maxhub Pivot