EIP-2026-116962

PRE-CVE

Cisco WebEx One-Click Client Password Encryption - Information Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116962. PoCs published by Brad Antoniewicz.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Cisco WebEx One-Click Client by decrypting stored passwords from the Windows registry using AES-OFB encryption. The code includes functional decryption logic and a test case to verify the exploit.

Description

Cisco WebEx One-Click Client Password Encryption - Information Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Brad Antoniewicz · clocalwindows
https://www.exploit-db.com/exploits/38668

This exploit demonstrates an information disclosure vulnerability in Cisco WebEx One-Click Client by decrypting stored passwords from the Windows registry using AES-OFB encryption. The code includes functional decryption logic and a test case to verify the exploit.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Cisco WebEx One-Click Client
No auth needed
Prerequisites: Access to the victim's registry keys (HKEY_CURRENT_USER\Software\WebEx\ProdTools\Password, PasswordLen, UserName, SiteName)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026