| CVE ID | CVE-2026-41874 |
| Publication date | 28 July 2026 |
| Vendor | OpenSolution |
| Product | Quick.Cart |
| Vulnerable versions | All through 6.7 |
| Vulnerability type (CWE) | Plaintext Storage of a Password (CWE-256) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in OpenSolution Quick.Cart software and participated in coordination of its disclosure.
The vulnerability CVE-2026-41874: Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation.
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.
Credits
We thank Karol Czubernat for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.