PT-2026-38219 · Vvveb+1 · Vvveb+1

·

CVE-2026-41930

·

Published

2026-05-06

·

Updated

2026-05-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vvveb versions prior to 1.0.8.2
Description A hard-coded credentials issue exists in the docker-compose-apache.yaml configuration. This allows unauthenticated attackers to access the bundled phpMyAdmin container using pre-configured database credentials. By connecting to the phpMyAdmin port, attackers can obtain unrestricted read and write access to the entire database, including administrator password hashes, customer personally identifiable information, and order data, which can lead to account takeover and data manipulation.
Recommendations Update to version 1.0.8.2 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41930
GHSA-G38H-MR9P-FJMF

Affected Products

Vvveb
Phpmyadmin