Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-105392
Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0029 19.5 —
AFFECTED
Product Versions Fixed
Django-Vue-Lyadmin 3.2.0 – —
TIMELINE
Oct 5 Reserved by VulDB
Oct 5 Published (CNA: VulDB)
Oct 6 EXPLOIT PUBLISHED — CVE-2026-105392 (Lybbn Django-Vue-Lyadmin). Public exploit reference added.
Description
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 5, 2026 | Reserved | Reserved by VulDB |
| October 5, 2026 | Published | Published (CNA: VulDB) |
| October 6, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-105392 (Lybbn Django-Vue-Lyadmin). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Lybbn | Django-Vue-Lyadmin | — | 3.2.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-105392 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.