ATLAS Landscape
AML.T0083

Credentials from AI Agent Configuration

Adversaries may access the credentials of other tools or services on a system from the configuration of an AI agent. AI Agents often utilize external tools or services to take actions, such as querying databases, invoking APIs, or interacting with cloud resources. To enable these functions, credentials like API keys, tokens, and connection strings are frequently stored in configuration files. While there are secure methods such as dedicated secret managers or encrypted vaults that can be deployed to store and manage these credentials, in practice they are often placed in less protected locations for convenience or ease of deployment. If an attacker can read or extract these configurations, they may obtain valid credentials that allow direct access to sensitive systems outside the agent itself.

Severity CVE CVSS
CRITICAL GHSA-wpqr-6v78-jr5g 10.0
CRITICAL CVE-2026-33663 10.0
CRITICAL CVE-2026-21858 10.0
CRITICAL CVE-2025-59528 10.0
CRITICAL CVE-2026-27494 9.9
CRITICAL CVE-2026-25115 9.9
CRITICAL CVE-2026-21877 9.9
CRITICAL CVE-2026-27495 9.9
CRITICAL CVE-2026-27577 9.9
CRITICAL CVE-2026-33309 9.9
CRITICAL CVE-2026-25053 9.9
CRITICAL CVE-2026-25052 9.9
CRITICAL CVE-2026-25049 9.9
CRITICAL CVE-2026-1470 9.9
CRITICAL CVE-2026-0863 9.9
CRITICAL CVE-2025-68668 9.9
CRITICAL CVE-2025-61260 9.8
CRITICAL CVE-2024-37014 9.8
CRITICAL CVE-2026-35022 9.8
CRITICAL CVE-2025-58434 9.8
CRITICAL CVE-2025-13374 9.8
CRITICAL CVE-2026-30824 9.8
CRITICAL CVE-2026-27966 9.8
CRITICAL CVE-2026-39890 9.8
CRITICAL CVE-2026-41276 9.8
CRITICAL CVE-2026-41267 9.8
CRITICAL CVE-2026-41268 9.8
CRITICAL CVE-2024-42835 9.8
CRITICAL CVE-2025-59434 9.6
CRITICAL CVE-2025-55526 9.1
CRITICAL CVE-2026-27825 9.1
CRITICAL CVE-2026-33749 9.0
CRITICAL CVE-2026-27493 9.0
HIGH CVE-2025-62726 8.8
HIGH CVE-2026-6543 8.8
HIGH CVE-2025-68613 8.8
HIGH CVE-2025-65964 8.8
HIGH CVE-2025-56265 8.8
HIGH CVE-2026-41269 8.8
HIGH CVE-2025-57760 8.8
HIGH CVE-2026-25056 8.8
HIGH CVE-2025-61687 8.8
HIGH CVE-2026-41137 8.8
HIGH CVE-2026-27498 8.8
HIGH CVE-2026-30820 8.8
HIGH CVE-2026-33696 8.8
HIGH CVE-2026-33713 8.8
HIGH CVE-2026-27497 8.8
HIGH CVE-2023-27563 8.8
HIGH GHSA-qwgj-rrpj-75xm 8.8
HIGH CVE-2026-25580 8.6
HIGH CVE-2024-32965 8.6
HIGH CVE-2026-39974 8.5
HIGH GHSA-8g7g-hmwm-6rv2 8.3
HIGH CVE-2025-68664 8.2
HIGH CVE-2026-29872 8.2
HIGH CVE-2026-33665 8.2
HIGH CVE-2026-41273 8.2
HIGH CVE-2024-28088 8.1
HIGH GHSA-48m6-ch88-55mj 8.1
HIGH CVE-2026-35021 7.8
HIGH CVE-2026-34222 7.7
HIGH GHSA-hr5v-j9h9-xjhg 7.7
HIGH CVE-2024-7959 7.7
HIGH CVE-2025-61917 7.7
HIGH CVE-2024-36420 7.5
HIGH CVE-2026-33497 7.5
HIGH CVE-2026-21852 7.5
HIGH CVE-2025-0330 7.5
HIGH CVE-2024-9606 7.5
HIGH CVE-2024-34510 7.5
HIGH CVE-2023-27564 7.5
HIGH CVE-2026-41279 7.5
HIGH CVE-2026-41278 7.5
HIGH CVE-2026-41275 7.5
HIGH CVE-2026-41266 7.5
HIGH CVE-2025-65098 7.4
HIGH CVE-2025-8709 7.3
HIGH GHSA-w8hx-hqjv-vjcq 7.3
HIGH CVE-2026-21893 7.2
HIGH CVE-2026-41272 7.1
HIGH GHSA-2x8m-83vc-6wv4 7.1
MEDIUM CVE-2026-27496 6.5
MEDIUM CVE-2025-14980 6.5
MEDIUM CVE-2026-25631 6.5
MEDIUM GHSA-mvv8-v4jj-g47j 6.5
MEDIUM CVE-2025-57749 6.5
MEDIUM CVE-2026-43570 6.5
MEDIUM CVE-2023-27562 6.5
MEDIUM CVE-2026-3346 6.4
MEDIUM CVE-2026-40117 6.2
MEDIUM CVE-2024-37146 6.1
MEDIUM CVE-2024-36423 6.1
MEDIUM CVE-2024-37145 6.1
MEDIUM GHSA-2qqc-p94c-hxwh 5.6
MEDIUM GHSA-cc4f-hjpj-g9p8 5.6
MEDIUM CVE-2026-40159 5.5
MEDIUM CVE-2026-44479 5.5
MEDIUM GHSA-cqmh-pcgr-q42f 5.5
MEDIUM CVE-2025-61914 5.4
MEDIUM CVE-2025-52478 5.4
MEDIUM GHSA-364x-8g5j-x2pr 5.4
MEDIUM CVE-2025-68697 5.4
MEDIUM CVE-2026-27578 5.4
MEDIUM CVE-2026-25051 5.4
MEDIUM CVE-2026-25054 5.4
MEDIUM CVE-2023-34094 5.3
MEDIUM GHSA-6pcv-j4jx-m4vx 5.3
MEDIUM CVE-2026-2589 5.3
MEDIUM CVE-2026-33722 5.3
MEDIUM CVE-2026-6598 4.3
MEDIUM GHSA-wg4g-395p-mqv3 4.3
MEDIUM CVE-2025-6854 4.3
MEDIUM CVE-2026-42282 4.3
LOW CVE-2026-4993 3.3
LOW CVE-2026-6597 2.7
MEDIUM GHSA-83f3-hh45-vfw9
MEDIUM GHSA-93rg-2xm5-2p9v
MEDIUM GHSA-55cf-xx38-4p9p
UNKNOWN CVE-2026-0772
MEDIUM GHSA-c28g-vh7m-fm7v
UNKNOWN CVE-2026-42231
UNKNOWN CVE-2026-42235
HIGH GHSA-x5w6-38gp-mrqh
UNKNOWN CVE-2026-42234
UNKNOWN CVE-2026-42227
MEDIUM GHSA-h2vw-ph2c-jvwf
LOW GHSA-j4c5-89f5-f3pm
HIGH GHSA-v4p8-mg3p-g94g
UNKNOWN CVE-2026-0769
UNKNOWN CVE-2024-12775
UNKNOWN CVE-2026-34046
UNKNOWN CVE-2026-30822
UNKNOWN CVE-2026-2285
UNKNOWN CVE-2026-30823
CRITICAL GHSA-xh72-v6v9-mwhc
HIGH CVE-2026-35629
UNKNOWN CVE-2025-11203
HIGH GHSA-f6hc-c5jr-878p
UNKNOWN CVE-2026-42226
HIGH GHSA-6f7g-v4pp-r667
MEDIUM GHSA-x783-xp3g-mqhp
HIGH GHSA-4jpm-cgx2-8h37
MEDIUM GHSA-3fv3-6p2v-gxwj
LOW GHSA-5fc7-f62m-8983
MEDIUM GHSA-vjx8-8p7h-82gr
UNKNOWN CVE-2026-0768
UNKNOWN CVE-2026-44694
LOW GHSA-767m-xrhc-fxm7