CVE-2026-18452 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-18452 | CVSS 10.0 (Critical) | Exploit: PoC available
What Is It
CVE-2026-18452 is a hard-coded credential vulnerability in Rich Source DMS+ (Non-Mobile) that exposes an API interface protected by a fixed API key.
Technical Detail
The product contains a static API key that can be used by an unauthenticated remote attacker to bypass intended authentication controls. An attacker who obtains and submits the fixed key to the affected API can gain control over all installed DMS+ devices. The reported impact is remote unauthorized administrative control of affected devices; no separate code-execution condition is specified in the available information.
Exploitation Status
A proof of concept is available. CISA has not listed CVE-2026-18452 in its Known Exploited Vulnerabilities Catalog as of July 31, 2026, and active exploitation in the wild has not been confirmed in the available data.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this as an urgent remediation priority because exploitation is unauthenticated, remote, and can affect all installed DMS+ devices. Obtain and apply a vendor-provided update or remediation from Rich Source that replaces the exposed credential and prevents use of a static API key. Until a fix is available, restrict access to DMS+ management and API interfaces to trusted administrative networks only, remove direct Internet exposure, enforce network segmentation, and limit access through firewall allowlists or VPN-controlled administration paths. Review API and device-management logs for authentication attempts or API requests using unexpected sources, particularly requests originating outside approved management networks. Confirm whether the deployed DMS+ version and exposed interfaces are affected, as detailed affected version information has not been provided.