CVE-2026-16504 Details
Description
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.
The VPS.org one-click deployment Zulip template contains several vulnerabilities, including a hardcoded application signing key, a default database password, and a configuration that disables HTTPS. The hardcoded key can be exploited for session forgery and authentication bypass, while the default database password allows unauthorized database access. Disabling HTTPS exposes sensitive data to interception.
Users are advised to change default passwords and secret keys before deploying to production. Implement firewall rules and network segmentation to restrict internet access to back-end systems like databases. Where applicable, enable HTTPS to protect credentials and session data in transit.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/243636 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | CISA-ADP |
| CWE-1393 | Use of Default Password | CISA-ADP |
| CWE-321 | Use of Hard-coded Cryptographic Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| VPS.org | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | [email protected] |
Volerion