Default Account Vulnerability in Newbee Mall by Newbee Ltd
CVE-2026-26218
9.3CRITICAL
What is CVE-2026-26218?
The Newbee Mall application inadvertently includes pre-seeded administrator accounts that are initialized with predictable default passwords in its database script. This oversight poses a significant security risk, as any deployment that uses the default database schema without modifying the administrative credentials can be exploited by unauthorized individuals. Attackers can potentially log in as an administrator, leading to total administrative control over the application's functionalities and data.
Affected Version(s)
newbee-mall 1.0.0
