Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-14807: PROG MIS ERP App Uses Hard-coded Login Credentials
CVE-2026-14807
CVE-2026-14807
Summary
The PROG MIS ERP App stores its login credentials directly in the code, which can be accessed by unauthorized users. This allows them to log in to the app and potentially view sensitive data. To protect the app, update the login credentials to be stored securely, such as in a database or encrypted file.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| prog mis | erp app | all |
Original title
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and pas...
Original description
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.
mitre CVSS3.1
9.8
Vulnerability type
CWE-798
Use of Hard-coded Credentials
- https://www.twcert.org.tw/tw/cp-132-11023-3abe8-1.html third-party-advisory
- https://www.twcert.org.tw/en/cp-139-11024-c5c1a-2.html third-party-advisory
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026