CVE-2026-4588 Details
Description
A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. This manipulation of the argument sk causes use of hard-coded cryptographic key . The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Kalcaddle Kodbox version 1.64 within the Site-Level API Key Handler component. The issue arises in the shareSafeGroup function of shareOut.class.php, where the manipulation of the sk parameter leads to the use of a hard-coded cryptographic key. This vulnerability can be exploited remotely, although the complexity of the attack is considered high. The exploit has been publicly disclosed and is available for use.
Kalcaddle Kodbox should be updated to remove the default key fallback, enforce a strong non-empty shareOutSiteApiKey, adopt robust AEAD-based token protection, and require proper authentication and authorization for all shareSafeGroup operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 23, 2026CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.352424 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?id.352424 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.775464 | [email protected] | Technical Description |
| https://vulnplus-note.wetolink.com/share/rM8GdIOvQZrw | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kalcaddle kodbox | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 23, 2026 | New CVE Received | [email protected] |
Volerion