CVE-2026-58466
Last modified
CVE-2026-58466 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can submit the default credentials to the authentication login endpoint to gain full control of the application, including RSS feed configuration, downloader configuration, and all authenticated API endpoints.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can submit the default credentials to the authentication login endpoint to gain full control of the application, including RSS feed configuration, downloader configuration, and all authenticated API endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| EstrellaXD | Auto_Bangumi | < 3.2.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-58466?
How severe is CVE-2026-58466?
How do I fix CVE-2026-58466?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58457Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) co…9.8
- CVE-2026-58459gpsd through release-3.27.5, fixed at commit 4c06658, contai…9.6
- CVE-2026-5846The affected Watchfire Controller Software contains self-sig…7.6
- CVE-2026-58460react-native-receive-sharing-intent contains a path traversa…7.7
- CVE-2026-58461Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-58465Eclipse Wakaama before snapshot/2026-05-26 contains an unbou…8.7
- CVE-2026-58467Cockpit CMS through 2.14.0 contains a path traversal and loc…8.2
- CVE-2026-58468NocoBase through 2.1.20 contains a server-side request forge…5.5
- CVE-2026-58469GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a…8.7
- CVE-2026-5847A vulnerability has been found in code-projects Movie Ticket…4.3
- CVE-2026-58470GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains a…6.9
- CVE-2026-58471GNU Wget through 1.25.0, fixed in commit c2640fe, contains a…7.1
Are you affected by CVE-2026-58466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
