HIGH
CVE-2026-90510
CVSS
8.3
Description
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key
. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Weakness (CWE)
CWE-320
CWE-321
EPSS Score
0.29%
Probability of exploitation in next 30 days
21.9th percentile
References
https://github.com/dromara/orion-visor/
https://github.com/dromara/orion-visor/issues/171
https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/Hardcoded%20AES%20Encryption%20Key%20Enables%20Decryption%20of%20SSH%20Private%20Keys%20and%20Host%20Passwords%20(CWE-321)_en.md
https://vuldb.com/cve/CVE-2026-90510
https://vuldb.com/submit/911865
https://vuldb.com/vuln/403098
https://vuldb.com/vuln/403098/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.