CVE-2026-41879
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-328
- Published
- 2026-07-10
- Last modified
- 2026-07-10
Affected products
- R-SOFT SERWIS DMS
Weakness type
Related vulnerabilities
- CVE-2026-15605 — wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
- CVE-2026-14742 — langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
- CVE-2026-14738 — exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
- CVE-2026-14630 — ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
- CVE-2026-10540 — Weak password hash protection in Control-M/Entreprise Manager
- CVE-2026-13455 — PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-13510 — SimStudioAI sim Password Protection deployment.ts weak hash