newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.
References
| Link | Resource |
|---|---|
| https://github.com/newbee-ltd/newbee-mall/issues/119 | Exploit Issue Tracking Vendor Advisory |
| https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover | Third Party Advisory |
Configurations
History
25 Feb 2026, 16:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/newbee-ltd/newbee-mall/issues/119 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover - Third Party Advisory | |
| Summary |
|
|
| First Time |
Newbee-mall Project
Newbee-mall Project newbee-mall |
|
| CPE | cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:* |
12 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 19:15
Updated : 2026-02-25 16:41
NVD link : CVE-2026-26218
Mitre link : CVE-2026-26218
CVE.ORG link : CVE-2026-26218
JSON object : View
Products Affected
newbee-mall_project
- newbee-mall
CWE
CWE-798
Use of Hard-coded Credentials
