CVE-2026-58466Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can submit the default credentials to the authentication login endpoint to gain full control of the application, including RSS feed configuration, downloader configuration, and all authenticated API endpoints.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-02: 3Mentions · 2026-07-03: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 3Technical Details · 2026-07-03: 107-0207-03
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-023
Disclosure2Patch1
2026-07-031
Patch1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58466 — CVSS 9.8/10 ██████████ AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/1PyZrWLY0O

    Post summary

    CVE‑2026‑58466 is a critical hard‑coded default credential flaw in AutoBangumi before 3.2.8 (CVSS 9.8/10) that has an available patch.

    1000097
    63 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - AutoBangumi Hard-Coded Default Admin Credentials (CVE-2026-58466) On startup, when its users table is empty, AutoBangumi's add_default_user() seeds a publicly known default administrator account. Since those credentials are documented/known and unchanged by default, an unauthenticated remote attacker can just submit them to the login endpoint and authenticate as admin. That grants full control of the application - RSS feed configuration, downloader configuration, and every authenticated API endpoint - with no privileges or user interaction required. Manipulating the downloader configuration is a natural pivot toward host-level impact. 👉Upgrade AutoBangumi to 3.2.8 and change any default admin credentials.

    Post summary

    The notice highlights a critical vulnerability in AutoBangumi involving default admin credentials that enable unauthenticated remote login, and it advises upgrading to version 3.2.8 to remediate the issue.

    0000087
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58466 AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using t… https://www.cve.org/CVERecord?id=CVE-2026-58466 ----- Traducción: CVE-2026-58466 Aut… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-58466, describing it as a hard‑coded credentials vulnerability, but does not provide PoC, exploit code, or patch information.

    0000036
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58466 AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using t… https://www.cve.org/CVERecord?id=CVE-2026-58466

    Post summary

    The announcement highlights a hard‑coded default credentials flaw in AutoBangumi versions before 3.2.8 that lets unauthenticated users gain admin access, but no PoC, exploit, active use, or patch details are provided.

    00000678
    57.7K followersView on X

Explore more