Critical severity9.1NVD Advisory· Published Feb 12, 2026· Updated Jul 14, 2026
CVE-2026-26219
CVE-2026-26219
Description
newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*range: <=1.0.0
- (no CPE)
- (no CPE)range: 1.0.0
Patches
Vulnerability mechanics
References
2- github.com/newbee-ltd/newbee-mall/issues/119nvdExploitIssue TrackingVendor Advisory
- www.vulncheck.com/advisories/newbee-mall-unsalted-md5-password-hashing-enables-offline-credential-crackingnvdThird Party Advisory
News mentions
0No linked articles in our index yet.