A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90510 exposes a critical cryptographic flaw in dromara Orion Visor versions up to 2.5.7, where the HostKeyServiceImpl.encryptKey function uses hard-coded cryptographic keys instead of dynamically generated or properly managed credentials. This vulnerability (CWE-320: Key Management Errors, CWE-321: Use of Hard-coded Cryptographic Key) affects organizations deploying Orion Visor for asset and host key management. Since the vulnerability enables remote exploitation and publicly disclosed proof-of-concept code exists, any system running the affected versions faces immediate risk of unauthorized access to encrypted host credentials, potentially compromising entire infrastructure management capabilities.
While this CVE currently maps to zero MITRE ATT&CK techniques in public documentation, Casky's skill framework trained on Claude AI would detect the attack patterns and defensive gaps associated with this vulnerability. Practitioners using Casky would identify related skills covering credential access, lateral movement initiation points, and cryptographic weakness detection—specifically around T1110 (Brute Force) attacks against weak key spaces, T1555 (Credentials from Password Stores) exploitation, and T1021 (Remote Service Session Initiation) once credentials are compromised. Security teams querying Casky would surface findings related to improper cryptographic implementation assessment, hard-coded secret scanning in source code repositories, and runtime detection of symmetric encryption with static keys—enabling proactive remediation before attackers chain this vulnerability into broader compromise scenarios.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90510. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation