HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-105392 — A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The imp...
·Source: NIST NVD
Updated:
Executive Summary
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The proj
Analysis
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." CVSS Score: 7.3. Published: 2026-10-05T20:17:10.827.