VDB

GCVE-110-BRLY-2026-014

GCVE-110-BRLY-2026-014
Advisory Published
Vulnetix · Advisory published September 3, 2026
BRLY-2026-014 Critical BINARLY REsearch team identified an exposed OpenAI API Key embedded in a container image hosted on Docker Hub under the `sapcom` namespace. The key was verified as valid and grants read and write access to multiple OpenAI API endpoints, including chat completions, embeddings, fine-tuning, file storage, and assistants. An attacker with access to this key could consume API credits, exfiltrate files and training data, tamper with fine-tuned models and assistant configurations, and read conversation threads. SAP's investigation determined that, in this specific case, the key belonged to a personal OpenAI developer account used for individual exploration and was not connected to SAP production systems, customer data, or corporate infrastructure.

Browse GCVE Records

556 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›