CVE-2026-35467 describes a vulnerability (CWE-522) where API keys, used as encryption credentials, are stored unprotected in temporary browser clients, allowing their extraction via client-side methods like the JavaScript console. While no official CVSS score is available, it carries a FAUCET Risk Score of 27.0/100, indicating a low-to-moderate severity due to the potential compromise of these sensitive credentials. There is currently no evidence of active exploitation, no public exploit code available on platforms like Metasploit or ExploitDB, and community discussion remains minimal with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.24CPE matchmatch criteria | cpe:2.3:a:cmu:cveclient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.