CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-26218

Critical · CVSS 9.8

newbee-mall — Hard-coded / Default Credentials (CWE-798)

CVSS
9.8
nvd
EPSS
0.37%
29th pct
KEV
No
Class
other
CWE-798

Description

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

Search profile — drives PoC discovery

Symbols database initialization scriptschemadefault administrative credentialspre-seeded administrator accountsadmin login
Keywords CVE-2026-26218newbee-malldefault credentialshardcoded credentialsseeded admin accountdatabase init scriptpredictable passwordadministrator takeovernewbee-mall PoCnewbee-mall exploit
Versions: <UNKNOWN>

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z