PT-2026-41204 · Electerm+1 · Electerm

Curly-Haired-Baboon

·

Published

2026-05-14

·

Updated

2026-06-03

·

CVE-2026-45787

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions electerm versions prior to 3.9.5
Description Insecure sync encryption occurs due to the use of deterministic AES-192-CBC with a fixed zero IV (Initialization Vector), a constant KDF (Key Derivation Function) salt, and the absence of a MAC (Message Authentication Code). This leads to confidentiality and integrity failures for synced bookmark and profile data. Attackers can crack common passwords across different installations and perform undetected ciphertext bit-flips to alter configurations and bookmarks.
Recommendations Update to version 3.9.5.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-45787
GHSA-G29V-Q6H7-76WH

Affected Products

Electerm