CVE-2026-82808CWE-259CWE-798hardcoded-credentials

CVE-2026-82808

High · published August 31, 2026

CVSS v3.1
7.3
EPSS
0%
Percentile
19.9
In the wild
Unconfirmed
What it is

A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand about the issue. The support explains, that "[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports."

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00278 · 19.9th percentile
Weaknesses
CWE-259 · Use of Hard-coded Password; CWE-798 · Use of Hard-coded Credentials
Published
2026-08-31T21:17Z
References (6)
EPSS history
Timeline
  • 02 SEP 03:40Z
    EPSS moved — → 0%
    epss
  • 31 AUG 16:15Z
    Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
    cvelistv5