OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-85153

CRITICAL · CVSS 9.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Schmooze app contains hardcoded credentials and cryptographic keys, making it vulnerable to exploitation by unauthenticated remote attackers who can decompile the application to extract sensitive information. This could lead to unauthorized access to backend and cloud resources, enabling attackers to forge client requests. Organizations using this application should prioritize remediation to mitigate the risk of significant security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85153
Severity
CRITICAL
CVSS
9.3
EPSS
N/A

Original NVD Description

This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.