Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26218

Опубликовано: 12 фев. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*
Версия до 1.0.0 (включая)

EPSS

Процентиль: 29%
0.00367
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
github
7 месяцев назад

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

EPSS

Процентиль: 29%
0.00367
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798