216.73.216.6

CVE-2026-26218

· Published 12/02/2026 19:15 · Modified 13/02/2026 14:23

Labels: CVE-2026-26218 2026-02-12CVE-2026-26218CWE-798[email protected]

Essential information

Published
12/02/2026 19:15
Modified
13/02/2026 14:23
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
newbee-mall / newbee-mall cpe:2.3:a:newbee-mall:newbee-mall:*:*:*:*:*:*:*:*

References