CVE-2026-50110 Details
Description
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning successful exploitation of this vulnerability could provide an attacker with unauthorized access to multiple interconnected systems.
A vulnerability exists in StoneFly Storage Concentrator (both SC and SCVM) versions prior to 8.0.4.26, due to hard-coded credentials for various internal services embedded in a configuration file. Although the credentials are encoded, the encoding can be easily reversed to plaintext. These credentials provide access to a range of internal services, including database accounts, licensing, replication services, and third-party integrations. Exploiting this vulnerability could allow unauthorized access to multiple interconnected systems.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| StoneFly Storage Concentrator | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
| StoneFly Storage Concentrator Virtual Machine | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion