CVE-2026-16504
N/A
N/A
Summary
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VPS.org | Zulip template | N/A | affected |
Weaknesses
- CWE-1188: Initialization of a Resource with an Insecure Default
- CWE-321: Use of Hard-coded Cryptographic Key
- CWE-1393: Use of Default Password
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.