CVE-2026-16581CWE-540
Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
Medium · published July 28, 2026
What it is
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
The record
Technical detail
- CVSS v4.0
- 6.9 · MEDIUM
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00225 · 13.1th percentile
- Weakness
- CWE-540 · Inclusion of Sensitive Information in Source Code
- Published
- 2026-07-28T20:05Z
EPSS history
Timeline