VYPR
Critical severity9.1NVD Advisory· Published Feb 12, 2026· Updated Jul 14, 2026

CVE-2026-26219

CVE-2026-26219

Description

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:newbee-mall_project:newbee-mall:*:*:*:*:*:*:*:*range: <=1.0.0
    • (no CPE)
    • (no CPE)range: 1.0.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.