Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsPresent
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | nvd | AV: P→N, AC: H→L, PR: H→N, UI: A→N, VC: N→H | 0.0 → 4.6 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| replicated | replicated_classic | ≥ 2.10.0, ≤ 2.32.3 |
| replicated | replicated_classic | ≥ 2.33.0, ≤ 2.36.0 |
| replicated | replicated_classic | ≥ 2.37.0, ≤ 2.37.1 |
| replicated | replicated_classic | ≥ 2.38.0, ≤ 2.38.5 |
| replicated | replicated_classic | ≥ 2.39.0, ≤ 2.39.3 |
| replicated | replicated_classic | ≥ 2.40.0, ≤ 2.40.3 |
| replicated | replicated_classic | ≥ 2.42.0, ≤ 2.42.3 |
| replicated | replicated_classic | 2.41.0 |
Published: 2021-07-28