๐Ÿ” CVE Alert

CVE-2026-26218

CRITICAL 9.8

newbee-mall Default Seeded Administrator Credentials Allow Account Takeover

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

CWE CWE-798
Vendor newbee-ltd
Product newbee-mall
Published Feb 12, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for newbee-ltd newbee-mall

Be the first to know when new critical vulnerabilities affecting newbee-ltd newbee-mall are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

newbee-ltd / newbee-mall
1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/newbee-ltd/newbee-mall/issues/119 vulncheck.com: https://www.vulncheck.com/advisories/newbee-mall-default-seeded-administrator-credentials-allow-account-takeover

Credits

Lennon Chia