HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105392 — A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The imp...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The proj

Analysis

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." CVSS Score: 7.3. Published: 2026-10-05T20:17:10.827.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105392
Source Attribution

Originally published by NIST NVD on Oct 5, 2026. Verified by: NIST.

Related Threats