CVE-2026-105392
Received
Received - Intake
Hard-Coded Cryptographic Key in Lybbn Django-Vue-Lyadmin
Vulnerability report for CVE-2026-105392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-05
Last updated on: 2026-10-05
Assigner: VulDB
Description
Description
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Lybbn | Django-Vue-Lyadmin | 3.2.0 |
| Lybbn | Django-Vue-Lyadmin | 3.2.1 |
| Lybbn | Django-Vue-Lyadmin | 3.2.2 |
| Lybbn | Django-Vue-Lyadmin | 3.2.3 |
| Lybbn | Django-Vue-Lyadmin | 3.2.4 |
| Lybbn | Django-Vue-Lyadmin | 3.2.5 |
| Lybbn | Django-Vue-Lyadmin | 3.2.6 |
| Lybbn | Django-Vue-Lyadmin | 3.2.7 |
| Lybbn | Django-Vue-Lyadmin | 3.2.8 |
| Lybbn | Django-Vue-Lyadmin | 3.2.9 |
| Lybbn | Django-Vue-Lyadmin | 3.2.10 |
| Lybbn | Django-Vue-Lyadmin | 3.2.11 |
| Lybbn | Django-Vue-Lyadmin | 3.2.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-320 | Key Management Errors |
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |