| CVE ID | CVE-2026-1958 |
| Publication date | 23 March 2026 |
| Vendor | BRI |
| Product | KlinikaXP and KlinikaXP Insertino |
| Vulnerable versions | KlinikaXP: all before 5.39.01.01 KlinikaXP Insertino: all before 3.1.0.1 |
| Vulnerability type (CWE) | Use of Hard-coded Credentials (CWE-798) |
| Report source | Report to CERT Polska |
Description
KlinikaXP is veterinary clinic software for managing appointments, records, and finances. KlinikaXP Insertino is a separate app installed on tablets or laptops that connects to the main system and allows clients to enter their data.
CERT Polska has received a report about vulnerability in KlinikaXP and KlinikaXP Insertino software and participated in coordination of its disclosure.
The vulnerability CVE-2026-1958: Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update.
This issue affects KlinikaXP: before 5.39.01.01. and KlinikaXP Insertino before 3.1.0.1
Beside removing the hardcoded credentials from the code, previously exposed credentials were also rotated preventing further attack attempts.
Credits
We thank Wojciech Giełda for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.