# KlinikaXP veterinary software exposed via hardcoded credentials

Published: 2026-03-23 · Severity: high · Sectors: healthcare
Canonical: https://vorant.io/reports/7b62ae9b-932a-55fb-b28b-7fe9bd9667a4/klinikaxp-veterinary-software-exposed-via-hardcoded-credentials

> Hard-coded credentials in KlinikaXP veterinary software allowed attackers to compromise FTP servers and potentially distribute malicious updates to client systems.

CERT Polska disclosed CVE-2026-1958, a critical vulnerability in KlinikaXP veterinary clinic management software and its companion application KlinikaXP Insertino. The flaw involved hard-coded credentials that granted unauthorized access to multiple internal services, most critically the FTP server hosting application update packages. An attacker exploiting these credentials could upload malicious updates that would be distributed and installed on client machines as legitimate software updates, creating a supply-chain attack scenario.

The vulnerability affected KlinikaXP versions before 5.39.01.01 and KlinikaXP Insertino versions before 3.1.0.1. The vendor has addressed the issue by removing the hard-coded credentials from the codebase and rotating the previously exposed credentials to prevent further exploitation attempts. The vulnerability was responsibly disclosed by security researcher Wojciech Giełda through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1958

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1958

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7b62ae9b-932a-55fb-b28b-7fe9bd9667a4/klinikaxp-veterinary-software-exposed-via-hardcoded-credentials.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
