← Voltar para CVEs
CVE-2026-26218
CRITICAL9.8
Descricao
newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado2/12/2026
Ultima modificacao2/25/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
newbee-mall_project:newbee-mall
Fraquezas (CWE)
CWE-798
Referencias
https://github.com/newbee-ltd/newbee-mall/issues/119(disclosure@vulncheck.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.