CVE-2026-26219

CRITICAL

newbee-mall - Info Disclosure

Title source: llm
STIX 2.1

Description

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.

Scores

CVSS v3 9.1
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-327
Status published
Products (1)
newbee-mall_project/newbee-mall < 1.0.0
Published Feb 12, 2026
Tracked Since Feb 18, 2026