CVE-2026-105392
Received Received - Intake

Hard-Coded Cryptographic Key in Lybbn Django-Vue-Lyadmin

Vulnerability report for CVE-2026-105392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Lybbn Django-Vue-Lyadmin 3.2.0
Lybbn Django-Vue-Lyadmin 3.2.1
Lybbn Django-Vue-Lyadmin 3.2.2
Lybbn Django-Vue-Lyadmin 3.2.3
Lybbn Django-Vue-Lyadmin 3.2.4
Lybbn Django-Vue-Lyadmin 3.2.5
Lybbn Django-Vue-Lyadmin 3.2.6
Lybbn Django-Vue-Lyadmin 3.2.7
Lybbn Django-Vue-Lyadmin 3.2.8
Lybbn Django-Vue-Lyadmin 3.2.9
Lybbn Django-Vue-Lyadmin 3.2.10
Lybbn Django-Vue-Lyadmin 3.2.11
Lybbn Django-Vue-Lyadmin 3.2.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-320 Key Management Errors
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a hard-coded cryptographic key (SECRET_KEY) in the settings.py file of the Lybbn Django-Vue-Lyadmin project up to version 3.2.12. The application uses this key for JWT signing, allowing attackers to forge tokens and impersonate users, particularly the superadmin account. The issue stems from developers failing to manually change the default key before deployment, exposing systems to unauthorized access.

Detection Guidance

Check the backend/application/settings.py file in your django-vue-lyadmin installation for a hard-coded SECRET_KEY value. Search for the SECRET_KEY variable in the file and verify if it matches a known default or hard-coded value. Additionally, inspect JWT tokens used in your application to ensure they are not signed with a predictable or hard-coded key.

Impact Analysis

An attacker can exploit this to forge JWT tokens and gain full administrative access to the system. This includes reading, modifying, or deleting sensitive data, creating persistent admin accounts, and accessing restricted endpoints. Since the SECRET_KEY is hard-coded and exposed in the public repository, any instance using default settings is vulnerable to remote attacks without authentication.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control. GDPR mandates strict controls over personal data access and integrity, while HIPAA requires safeguards for sensitive health information. The ability to impersonate admins and access unauthorized data could lead to breaches, resulting in legal penalties, reputational damage, and loss of certification for affected organizations.

Mitigation Strategies

Immediately change the SECRET_KEY in backend/application/settings.py to a strong, randomly generated value. Ensure the new key is set before any imports or configurations that depend on it. Update your JWT configuration to explicitly define a SIGNING_KEY separate from SECRET_KEY if using django-restframework-simplejwt. Rotate all existing JWT tokens and invalidate any sessions that may have been compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart