CVE-2026-71238
9.1 CRITICALpublic exploit availablePublished 2026-08-05 · Updated 2026-08-10
AI risk analysis
- Summary
- The flaw lies in DjangoCRM hardcoding the Django SECRET_KEY in the settings.py file, allowing anyone to read the public repository to forge session cookies, CSRF tokens, and password reset tokens, leading to full account takeover.
- Exploitability
- Exploitation is relatively straightforward as anyone with access to the public repository can read the hardcoded key, making it easy to forge valid session cookies and other tokens.
- Blast radius
- If exploited, the impact is severe as it allows full account takeover, potentially compromising all user accounts, including the superadmin account.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of DjangoCRM that addresses this issue, ensuring the SECRET_KEY is read from an environment variable.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-798
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- HIGHCVE-2026-61687PoC
- HIGHCVE-2026-62062
- HIGHCVE-2026-78295
- CRITICALCVE-2026-80154
- CRITICALCVE-2026-82311PoC
- CRITICALCVE-2026-86462PoC
- CRITICALCVE-2026-76708
Related by shared AI tags and CWE weakness class. Browse the full archive.