VDB
GCVE-110-BRLY-2026-014
GCVE-110-BRLY-2026-014
Advisory Published
BRLY-2026-014 Critical BINARLY REsearch team identified an exposed OpenAI API Key embedded in a container image hosted on Docker Hub under the `sapcom` namespace. The key was verified as valid and grants read and write access to multiple OpenAI API endpoints, including chat completions, embeddings, fine-tuning, file storage, and assistants. An attacker with access to this key could consume API credits, exfiltrate files and training data, tamper with fine-tuned models and assistant configurations, and read conversation threads. SAP's investigation determined that, in this specific case, the key belonged to a personal OpenAI developer account used for individual exploration and was not connected to SAP production systems, customer data, or corporate infrastructure.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.