CVE-2026-26219Disclosure(newbee-mall_project / newbee-mall)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch newbee-mall_project newbee-mall systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • newbee-mall

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
newbee-mall

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-13: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 102-1202-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-122
Disclosure2
2026-02-131
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26219 newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost c… https://www.cve.org/CVERecord?id=CVE-2026-26219

    Post summary

    The post discloses that newbee‑mall’s authentication uses unsalted MD5 hashing for passwords, indicating a weak credential storage vulnerability. No proof‑of‑concept, exploit, patch, or active exploitation is reported.

    00020144
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-26219 in newbee-mall 1.0.0 uses unsalted MD5 for passwords — enabling rapid credential compromise if hashes leak. Patch now, enforce strong auth! 🔒 https://radar.offseq.com/threat/cve-2026-26219-cwe-327-use-of-a-broken-or-risky-cr-46123275 #OffSeq #infosec... https://t.co/0lW1Tn0yAo

    Post summary

    The tweet warns of a critical vulnerability in newbee-mall 1.0.0 that uses unsalted MD5 passwords, urging users to apply patches immediately.

    0000045
    268 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26219: CRITICAL] Newbee-mall's insecure password storage using unsalted MD5 hashing leaves user credentials vulnerable to cyber attacks from leaked databases. #CyberSecurity#cve,CVE-2026-26219,#cybersecurity https://cvefind.com/CVE-2026-26219

    Post summary

    The message discloses that Newbee‑mall stores passwords insecurely with unsalted MD5, exposing credentials to leaks, but offers no exploit, evidence of active attacks, or remediation guidance.

    0000040
    583 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnewbee-mall_projectnewbee-mall---

Explore more