PT-2026-39740 · Unknown · Amazon::Credentials

Robert Rothenberg

·

Published

2026-05-11

·

Updated

2026-05-15

·

CVE-2026-6146

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amazon::Credentials versions prior to 1.3.0
Description Amazon::Credentials stores credentials in an obfuscated form to prevent secrets from being accessed via a data dump of the object. The software uses a 64-bit key generated by the built-in rand function to encrypt these secrets. The rand function is predictable and unsuitable for cryptographic purposes.
Recommendations Update to version 1.3.0 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-6146

Affected Products

Amazon::Credentials