CVE-2026-105392
CVE-2026-105392 is a high-severity vulnerability with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-320.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- CVSS v2: 7.5
- CVSS v4: 5.5
- EPSS exploit prediction: 0% (20th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-320
- Published:
- Last modified:
Description
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Frequently asked questions
- What is CVE-2026-105392?
- A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
- How severe is CVE-2026-105392?
- CVE-2026-105392 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-105392 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (20th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-105392?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-105392 published?
- CVE-2026-105392 was published on 2026-10-05 and last updated on 2026-10-06.
References
- https://github.com/lybbn/django-vue-lyadmin/
- https://github.com/lybbn/django-vue-lyadmin/issues/3
- https://vuldb.com/cve/CVE-2026-105392
- https://vuldb.com/submit/982747
- https://vuldb.com/vuln/413586
- https://vuldb.com/vuln/413586/cti
Other CWE-320 vulnerabilities
- CVE-2016-10467 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD…
- CVE-2016-10421 — Critical (CVSS 9.8): In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206,…
- CVE-2018-0124 — Critical (CVSS 9.8): A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to…
- CVE-2015-0936 — Critical (CVSS 9.8): Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows…
- CVE-2015-4166 — Critical (CVSS 9.8): Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have…
- CVE-2024-36391 — Critical (CVSS 9.1): MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic