PT-2026-38219 · Unknown+1 · Phpmyadmin+1
Basant Kumar
+2
·
Published
2026-05-06
·
Updated
2026-05-13
·
CVE-2026-41930
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vvveb versions prior to 1.0.8.2
Description
A hard-coded credentials issue exists in the
docker-compose-apache.yaml configuration. This allows unauthenticated attackers to access the bundled phpMyAdmin container using pre-configured database credentials. By connecting to the phpMyAdmin port, attackers can obtain unrestricted read and write access to the entire database, including administrator password hashes, customer personally identifiable information, and order data, which can lead to account takeover and data manipulation.Recommendations
Update to version 1.0.8.2 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vvveb
Phpmyadmin