Default Account Vulnerability in Newbee Mall by Newbee Ltd
CVE-2026-26218

9.3CRITICAL

Key Information:

Vendor

Newbee-ltd

Vendor
CVE Published:
12 February 2026

What is CVE-2026-26218?

The Newbee Mall application inadvertently includes pre-seeded administrator accounts that are initialized with predictable default passwords in its database script. This oversight poses a significant security risk, as any deployment that uses the default database schema without modifying the administrative credentials can be exploited by unauthorized individuals. Attackers can potentially log in as an administrator, leading to total administrative control over the application's functionalities and data.

Affected Version(s)

newbee-mall 1.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lennon Chia
.