CVE-2026-5128 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
A vulnerability allowing sensitive information exposure exists in ArthurFiorette Steam-Trader version 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to access highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. Additionally, application logs reveal authentication artifacts such as access tokens, refresh tokens, and session identifiers. This information enables an attacker to generate valid Steam Guard (2FA) codes, hijack authenticated sessions, and gain full control over the affected Steam account, including unauthorized access to inventory and trading functionality.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Mar 31, 2026 | CVE Rejected | TuranSec |
| Mar 31, 2026 | CVE Modified | TuranSec |
| Mar 30, 2026 | New CVE Received | TuranSec |