CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-26219

Critical · CVSS 9.1

newbee-mall — Unsalted MD5 password hashing enabling offline credential cracking

CVSS
9.1
nvd
EPSS
0.19%
9th pct
KEV
No
Class
other
CWE-327

Description

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.

Search profile — drives PoC discovery

Symbols MD5passwordunsaltedhashnewbee-mallMD5UtilDigestUtilstb_newbee_mall_admin_usertb_newbee_mall_user
Keywords CVE-2026-26219newbee-mallunsalted MD5password hashingCWE-327credential crackingoffline attackhash recoverynewbee-ltdplaintext credentials
Versions: unspecified (all known public versions as of advisory date)

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z