CVE-2026-26219

Severity CVSS v4.0:
CRITICAL
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
12/02/2026
Last modified:
13/02/2026

Description

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.