VORANT. Threat Intelligence Sign in Get the full feed

Hard-coded creds threaten KlinikaXP update chain

medium vulnerability healthcare

A hard-coded credentials flaw in veterinary software KlinikaXP could have let attackers upload malicious updates to client machines via its FTP server.

CERT Polska coordinated disclosure of CVE-2026-1958, a vulnerability in KlinikaXP and its companion app KlinikaXP Insertino, used by veterinary clinics to manage appointments, records, and finances. The flaw stems from hard-coded credentials embedded in the software, which granted unauthorized access to several internal services, including the FTP server hosting official update packages.

The practical risk was significant: an attacker with access to the exposed credentials could have uploaded a malicious update file to the FTP server, which would then be distributed and installed on client machines as a legitimate software update — a classic supply-chain compromise vector. The vendor has since removed the hard-coded credentials from the codebase and rotated the previously exposed credentials to prevent further exploitation attempts.

The issue affects KlinikaXP versions before 5.39.01.01 and KlinikaXP Insertino versions before 3.1.0.1. There is no indication in the advisory that this vulnerability was actively exploited in the wild; it was reported responsibly by researcher Wojciech Giełda and resolved through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2026-1958

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1958

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free