CVE-2026-26218

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*

History

25 Feb 2026, 16:41

Type Values Removed Values Added
References () https://github.com/newbee-ltd/newbee-mall/issues/119 - () https://github.com/newbee-ltd/newbee-mall/issues/119 - Exploit, Issue Tracking, Vendor Advisory
References () https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover - () https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover - Third Party Advisory
Summary
  • (es) newbee-mall incluye cuentas de administrador precargadas en su script de inicialización de base de datos. Estas cuentas se aprovisionan con una contraseña predeterminada predecible. Las implementaciones que inicializan o restablecen la base de datos utilizando el esquema proporcionado y no cambian las credenciales administrativas predeterminadas pueden permitir a atacantes no autenticados iniciar sesión como administrador y obtener control administrativo total de la aplicación.
First Time Newbee-mall Project
Newbee-mall Project newbee-mall
CPE cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*

12 Feb 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 19:15

Updated : 2026-02-25 16:41


NVD link : CVE-2026-26218

Mitre link : CVE-2026-26218

CVE.ORG link : CVE-2026-26218


JSON object : View

Products Affected

newbee-mall_project

  • newbee-mall
CWE
CWE-798

Use of Hard-coded Credentials