CVE-2026-26218

CRITICAL

newbee-mall - Info Disclosure

Title source: llm
STIX 2.1

Description

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

Scores

CVSS v3 9.8
EPSS 0.0020
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
newbee-mall_project/newbee-mall < 1.0.0
Published Feb 12, 2026
Tracked Since Feb 18, 2026