August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2016-20026NVD

Vulnerability Summary

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.
Severity Level
CRITICAL(9.3)
Published Date
Mar 16, 2026
Last Modified
Mar 16, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.05%Probability
Root Weakness (CWE)
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS v4.0 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone