A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-19851 is a use of default password vulnerability in Tuleap Enterprise Edition versions 17.0 through 17.5 that affects user accounts created during XML import operations. When administrators import users via XML, the system assigns default credentials that attackers can exploit to gain unauthorized access. This is particularly dangerous because XML import is a common operational workflow for onboarding users at scale, meaning affected organizations may have multiple compromised accounts without realizing it. The vulnerability carries a CVSS score of 7.7 (high severity) and impacts any organization using Tuleap Enterprise within the affected version range, particularly those that actively use XML-based user provisioning for bulk account creation.
While this CVE currently has zero matching Casky skills and no mapped MITRE ATT&CK techniques, practitioners using Casky.ai with Claude's extended reasoning capabilities would detect attack patterns associated with this vulnerability through behavioral analysis. The attack chain would typically involve T1078 (Valid Accounts) once default credentials are compromised, potentially followed by T1526 (Find and Enumerate Cloud Resources) or T1087 (Account Discovery) as attackers explore their access. Practitioners should monitor for: unusual authentication events immediately after XML import operations, successful logins with newly created accounts from unexpected locations or times, and privilege escalation attempts from recently imported user accounts. Casky's AI-driven analysis would flag the temporal correlation between XML import activities and subsequent account access patterns as suspicious baseline deviations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19851. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation