VPS.org Zulip Template Flaw Exposes Sensitive Credentials
CVE-2026-16504
Currently unrated
What is CVE-2026-16504?
The VPS.org Zulip template deployment includes hardcoded application signing keys and a default database password of 'zulip', alongside a setting that disables HTTPS. These oversights significantly increase the risk of unauthorized access and potential data exposure.
Affected Version(s)
Zulip template
