What is CVE-2026-41874?
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. Attackers with access to the server file system can retrieve these details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low.
Azərbaycanca: Quick.Cart konfiqurasiya faylında düz mətn şəklində kodlaşdırılmış admin giriş məlumatları saxlayır. Server fayl sisteminə çıxışı olan hücumçular bu hesabları ələ keçirərək imtiyaz artımı əldə edə bilər. Vendor istismar ehtimalını çox aşağı qiymətləndirib.
Related CVEs
link basis: same weakness class CWE-798
FAQ1
What is the Quick.Cart CVE-2026-41874 vulnerability and how can it be exploited?
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. Attackers with access to the server file system can retrieve these details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.