VDB

GCVE-110-BRLY-2026-017

GCVE-110-BRLY-2026-017
Advisory Published
Vulnetix · Advisory published September 3, 2026
BRLY-2026-017 High BINARLY REsearch team identified two Azure AD client secrets, along with an RSA private key, embedded in container images hosted on Docker Hub under the `ciscosecurity` namespace. Both Azure AD client secrets were flagged as expired at the time of discovery. Test data shipped in the same images references an internal lab domain and QA automation accounts, suggesting these credentials belong to a Cisco internal QA environment. Regardless, the exposure reveals a build pipeline issue where credentials are baked into publicly accessible container images.

Browse GCVE Records

556 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›