Weak Password Hashing in Newbee Mall by Newbee Ltd
CVE-2026-26219

9.3CRITICAL

Key Information:

Vendor

Newbee-ltd

Vendor
CVE Published:
12 February 2026

What is CVE-2026-26219?

Newbee Mall employs an unsalted MD5 hashing algorithm for storing and verifying user passwords. This approach lacks individual salts and computational cost controls, making it susceptible to offline attacks. If password hashes are accessed through database breaches or backup leaks, attackers can swiftly recover plaintext credentials, posing significant risks to user security.

Affected Version(s)

newbee-mall 1.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lennon Chia
.