PT-2026-6732 · Infor · Infor Syteline Erp
Daniel Mansur
+2
·
Published
2026-02-06
·
Updated
2026-04-09
·
CVE-2026-2103
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Infor SyteLine ERP (affected versions not specified)
Description
The software utilizes hard-coded, static cryptographic keys for encrypting stored credentials, including user passwords, database connection strings, and API keys. These encryption keys are consistent across all installations. An attacker gaining access to the application binary and database can decrypt all stored credentials. This impacts all installations of the software, as the keys are universal.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infor Syteline Erp