CRITICALVulnerability

CVE-2026-71238

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover.

Properties

severity
CRITICAL
score
9.1
cve_id
CVE-2026-71238
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-05T11:16:26.630
last_modified
2026-08-26T17:13:24.800

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Credentials

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71238 — Ninja Signal Threat Intelligence | Ninja Signal