VDB
GCVE-110-BRLY-2026-017
GCVE-110-BRLY-2026-017
Advisory Published
BRLY-2026-017 High BINARLY REsearch team identified two Azure AD client secrets, along with an RSA private key, embedded in container images hosted on Docker Hub under the `ciscosecurity` namespace. Both Azure AD client secrets were flagged as expired at the time of discovery. Test data shipped in the same images references an internal lab domain and QA automation accounts, suggesting these credentials belong to a Cisco internal QA environment. Regardless, the exposure reveals a build pipeline issue where credentials are baked into publicly accessible container images.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.