CVE-2026-58466 Details
Description
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can submit the default credentials to the authentication login endpoint to gain full control of the application, including RSS feed configuration, downloader configuration, and all authenticated API endpoints.
A hard-coded default credentials vulnerability has been identified in AutoBangumi versions prior to 3.2.8. This vulnerability allows unauthenticated attackers to log in as administrators by using default credentials that are automatically added to the database when the users table is empty. Exploitation of this vulnerability grants full control over the application, including management of RSS feeds, downloader settings, and access to all authenticated API endpoints.
Users are advised to update AutoBangumi to version 3.2.8 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 2, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/EstrellaXD/Auto_Bangumi/commit/487bdfec545e805ae416e6ddf28651bd274d6a73 | [email protected] | Source CodeVendor |
| https://github.com/EstrellaXD/Auto_Bangumi/issues/1041 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/EstrellaXD/Auto_Bangumi/releases/tag/3.2.8 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/autobangumi-hard-coded-default-credentials-via-add-default-user | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutoBangumi | < 3.2.8 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | [email protected] |
Volerion