A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90498 represents a critical authentication bypass vulnerability in Lenve VHR 1.0-SNAPSHOT, where hardcoded or default credentials are embedded in the vhr.sql database initialization file. This vulnerability allows unauthenticated attackers to gain unauthorized access to the application with legitimate user credentials without requiring password cracking or social engineering. Organizations deploying Lenve VHR are at immediate risk, particularly those exposing the application to untrusted networks. The public availability of exploit code combined with the vendor's non-response significantly increases the likelihood of active exploitation in the wild.
While this CVE does not map to specific MITRE ATT&CK techniques in the current framework, Casky.ai's security skills trained on Claude AI would detect reconnaissance and credential access patterns associated with this vulnerability class. Practitioners using Casky would observe findings related to CWE-1392 (Use of Default Credentials) patterns, including SQL file discovery, database connection attempts using common default usernames, and lateral movement activities following initial authentication. Although Casky reports zero direct skill matches for this specific CVE, the platform's extended reasoning capabilities enable detection of behavioral indicators typical of default credential exploitation: unusual database query patterns, privilege escalation attempts immediately after login, and data exfiltration activities that follow successful authentication with factory-default account credentials.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90498. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation