CVE-2026-26218

n

ewbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

Configurations

Configuration 1 (hide)

cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*

History

25 Feb 2026, 16:41

Type Values Removed Values Added
First Time Newbee-mall Project newbee-mall
Newbee-mall Project
Summary
  • (es) newbee-mall incluye cuentas de administrador precargadas en su script de inicialización de base de datos. Estas cuentas se aprovisionan con una contraseña predeterminada predecible. Las implementaciones que inicializan o restablecen la base de datos utilizando el esquema proporcionado y no cambian las credenciales administrativas predeterminadas pueden permitir a atacantes no autenticados iniciar sesión como administrador y obtener control administrativo total de la aplicación.
CPE cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*
References () https://github.com/newbee-ltd/newbee-mall/issues/119 - () https://github.com/newbee-ltd/newbee-mall/issues/119 - Exploit, Issue Tracking, Vendor Advisory
References () https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover - () https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover - Third Party Advisory

13 Feb 2026, 14:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 19:15

Updated : 2026-02-25 16:41


NVD link : CVE-2026-26218

Mitre link : CVE-2026-26218

CVE.ORG link : CVE-2026-26218


JSON object : View

Products Affected
CWE
CWE-798

Use of Hard-coded Credentials