CVE-2026-103548

Improperly Stored Credentials

Severity
Medium 5.3
CVSS 4.0
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
—
Discovered by
Unknown
Vendor-published field
Published
Sep 30, 2026
Assigned by palo_alto

Description

Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.

Weakness: CWE-257CWE-260CWE-261

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • Itron · MV-90 xi

Credit

Menachem (Momo) Rothbart

Something wrong here?