A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Fri, 01 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials | |
| First Time appeared |
Astrbot
Astrbot astrbot |
|
| Weaknesses | CWE-259 CWE-798 |
|
| CPEs | cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Astrbot
Astrbot astrbot |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-01T11:30:15.357Z
Reserved: 2026-05-01T06:07:28.530Z
Link: CVE-2026-7579
No data.
Status : Deferred
Published: 2026-05-01T12:16:17.027
Modified: 2026-05-01T15:26:24.553
Link: CVE-2026-7579
No data.
OpenCVE Enrichment
Updated: 2026-05-01T12:30:16Z