| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-57263 | 6.8 | medium |
CVE-2026-57263. The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.
|
| CVE-2026-57262 | 6.8 | medium |
CVE-2026-57262. Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
|