Critical Alert 3 Active Exploits Detected Today

CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability →
CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability →
CVE-2026-9198 IBM Langflow Code Injection Vulnerability →
Powered by CVE Watchtower
×
August 5, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-71238NVD

Vulnerability Summary

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover. The repository also ships with DEBUG=True as the default, causing error pages to leak database credentials, email credentials, OAuth data, and internal file paths.
Severity Level
CRITICAL(9.1)
Published Date
Aug 5, 2026
Last Modified
Aug 5, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone