{"id":"CVE-2026-71238","published":"2026-08-05T11:16:26.630","lastModified":"2026-08-10T12:17:26.307","description":"DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-798"],"vendors":[],"products":[],"references":[{"url":"https://github.com/DjangoCRM/django-crm","tags":[]}],"exploitRefs":[{"url":"https://github.com/DjangoCRM/django-crm","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw lies in DjangoCRM hardcoding the Django SECRET_KEY in the settings.py file, allowing anyone to read the public repository to forge session cookies, CSRF tokens, and password reset tokens, leading to full account takeover.","exploitability":"Exploitation is relatively straightforward as anyone with access to the public repository can read the hardcoded key, making it easy to forge valid session cookies and other tokens.","blast_radius":"If exploited, the impact is severe as it allows full account takeover, potentially compromising all user accounts, including the superadmin account.","remediation":"Upgrade to the latest version of DjangoCRM that addresses this issue, ensuring the SECRET_KEY is read from an environment variable.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","secret-key","csrf","session"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:09:42.369Z"}}