A Use of Hard-coded Credentials vulnerability has been identified in TMT Machine Industry and Trade Ltd. Co.'s Talassoft Industrial Management Software. The vulnerability allows attackers to retrieve embedded sensitive data through the hard-coded credentials present in the software. Affected versions span from V.4 up to but not including V.16. The vulnerability is classified under CWE for hard-coded credentials and enables the 'Retrieve Embedded Sensitive Data' attack pattern. This is an industrial management software product, making the exposure of sensitive credentials particularly impactful for industrial environments. The issue has been assigned CVE-2026-18931 and is tracked by the Turkish cybersecurity authority (siberguvenlik.gov.tr). Users are advised to upgrade to V.16 or later to mitigate the risk.