EIP-2026-103818

PRE-CVE

Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103818. PoCs published by Tess Sluyter.

AI-analyzed exploit summary This Java exploit decrypts Tibco ObfuscationEngine 5.11x passwords encrypted with a fixed key. It uses a hardcoded DESede key and IV to reverse the obfuscation, exposing plaintext credentials from strings starting with '#!'.

Description

Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption

Exploits (1)

exploitdb WORKING POC
by Tess Sluyter · javalocalmultiple
https://www.exploit-db.com/exploits/49221

This Java exploit decrypts Tibco ObfuscationEngine 5.11x passwords encrypted with a fixed key. It uses a hardcoded DESede key and IV to reverse the obfuscation, exposing plaintext credentials from strings starting with '#!'.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Tibco ObfuscationEngine 5.11x and earlier
No auth needed
Prerequisites: Exfiltrated Tibco password strings starting with '#!'
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026