CVE-2026-16504

Summary

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Affected Software

VendorProductVersion RangeStatus
VPS.orgZulip templateN/Aaffected

Weaknesses

  • CWE-1188: Initialization of a Resource with an Insecure Default
  • CWE-321: Use of Hard-coded Cryptographic Key
  • CWE-1393: Use of Default Password

References