CVE-2026-26218Disclosure(newbee-mall_project / newbee-mall)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch newbee-mall_project newbee-mall systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • newbee-mall

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
newbee-mall

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-15: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-15: 102-1202-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-122
Disclosure2
2026-02-151
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26218 newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Depl… https://www.cve.org/CVERecord?id=CVE-2026-26218

    Post summary

    The post discloses CVE‑2026‑26218, noting that newbee‑mall ships with pre‑seeded administrator accounts using predictable default passwords.

    00010159
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26218: newbee-mall Default Seeded Admin... Default admin creds in newbee-mall's DB init scripts hand over full administrative control to anyone who can reach your... https://zerodaysignal.com/vulnerability/CVE-2026-26218 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑26218, noting that default admin credentials in newbee‑mall’s DB initialization scripts allow full administrative access.

    0000069
    131 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26218: CRITICAL] Ensure cyber security: Newbee-mall's database includes default admin accounts with predictable passwords. Change these credentials to prevent unauthorized access and protect your a...#cve,CVE-2026-26218,#cybersecurity https://cvefind.com/CVE-2026-26218

    Post summary

    The tweet announces CVE-2026-26218, detailing default admin credentials in Newbee-mall's database and recommends changing them to mitigate unauthorized access.

    0000038
    583 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnewbee-mall_projectnewbee-mall---

Explore more