PT-2026-6732 · Infor · Infor Syteline Erp

Daniel Mansur

+2

·

Published

2026-02-06

·

Updated

2026-04-09

·

CVE-2026-2103

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infor SyteLine ERP (affected versions not specified)
Description The software utilizes hard-coded, static cryptographic keys for encrypting stored credentials, including user passwords, database connection strings, and API keys. These encryption keys are consistent across all installations. An attacker gaining access to the application binary and database can decrypt all stored credentials. This impacts all installations of the software, as the keys are universal.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2103

Affected Products

Infor Syteline Erp