VPS.org Zulip Template Flaw Exposes Sensitive Credentials
CVE-2026-16504

Currently unrated

Key Information:

Vendor

Vps.org

Vendor
CVE Published:
31 July 2026

What is CVE-2026-16504?

The VPS.org Zulip template deployment includes hardcoded application signing keys and a default database password of 'zulip', alongside a setting that disables HTTPS. These oversights significantly increase the risk of unauthorized access and potential data exposure.

Affected Version(s)

Zulip template

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.