No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 31 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand about the issue. The support explains, that "[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports." | |
| Title | Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials | |
| First Time appeared |
Inbox Foundry
Inbox Foundry activeinbox Extension |
|
| Weaknesses | CWE-259 CWE-798 |
|
| CPEs | cpe:2.3:a:inbox_foundry:activeinbox_extension:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Inbox Foundry
Inbox Foundry activeinbox Extension |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T19:02:39.743Z
Reserved: 2026-08-31T04:48:20.500Z
Link: CVE-2026-82808
Updated: 2026-08-31T19:02:00.704Z
Status : Received
Published: 2026-08-31T17:17:46.970
Modified: 2026-08-31T20:17:14.390
Link: CVE-2026-82808
No data.
OpenCVE Enrichment
Updated: 2026-08-31T17:45:02Z