nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18915 CVE-2026-18915
MEDIUM
Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
Record summary
CVE-2026-18915 has a selected CVSS score of 5.0 (medium).
Description
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 1.0.4 | affected |
References
2siberguvenlik.gov.trGovernment resource
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0753