PT-2026-39740 · Unknown · Amazon::Credentials

·

CVE-2026-6146

·

Published

2026-05-11

·

Updated

2026-05-15

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amazon::Credentials versions prior to 1.3.0
Description Amazon::Credentials stores credentials in an obfuscated form to prevent secrets from being accessed via a data dump of the object. The software uses a 64-bit key generated by the built-in rand function to encrypt these secrets. The rand function is predictable and unsuitable for cryptographic purposes.
Recommendations Update to version 1.3.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6146

Affected Products

Amazon::Credentials