Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password hashes, customer personally identifiable information, and order data, enabling account takeover and data manipulation.
References
Configurations
No configuration.
History
06 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/givanz/Vvveb/security/advisories/GHSA-g38h-mr9p-fjmf - |
06 May 2026, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 19:16
Updated : 2026-05-06 20:16
NVD link : CVE-2026-41930
Mitre link : CVE-2026-41930
CVE.ORG link : CVE-2026-41930
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
