← Back to search

CVE-2026-71238

9.1 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw lies in DjangoCRM hardcoding the Django SECRET_KEY in the settings.py file, allowing anyone to read the public repository to forge session cookies, CSRF tokens, and password reset tokens, leading to full account takeover.
Exploitability
Exploitation is relatively straightforward as anyone with access to the public repository can read the hardcoded key, making it easy to forge valid session cookies and other tokens.
Blast radius
If exploited, the impact is severe as it allows full account takeover, potentially compromising all user accounts, including the superadmin account.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of DjangoCRM that addresses this issue, ensuring the SECRET_KEY is read from an environment variable.
auth-bypasswebsecret-keycsrfsession

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-798

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.