PT-2026-38219 · Unknown+1 · Phpmyadmin+1

Basant Kumar

+2

·

Published

2026-05-06

·

Updated

2026-05-13

·

CVE-2026-41930

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.2
Description A hard-coded credentials issue exists in the docker-compose-apache.yaml configuration. This allows unauthenticated attackers to access the bundled phpMyAdmin container using pre-configured database credentials. By connecting to the phpMyAdmin port, attackers can obtain unrestricted read and write access to the entire database, including administrator password hashes, customer personally identifiable information, and order data, which can lead to account takeover and data manipulation.
Recommendations Update to version 1.0.8.2 or later.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-41930

Affected Products

Vvveb
Phpmyadmin