CVE-2026-104356
Received Received - Intake

Weak Randomness in PictShare Generates Predictable Delete Tokens

Vulnerability report for CVE-2026-104356, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PictShare before version 3.7.1 has a weak randomness issue in the getRandomString() function. It uses the insecure rand() PRNG to generate delete_code tokens for file deletion authorization. Attackers can predict these tokens by exploiting the predictable PRNG state, allowing unauthorized file deletions without accessing the info endpoint.

Detection Guidance

To detect this vulnerability, check if your PictShare instance is running a version before 3.7.1. Inspect the src/inc/core.php file for the getRandomString() function using rand() for delete_code generation. Monitor logs for unauthorized file deletion attempts or unusual access patterns.

Impact Analysis

If you use PictShare before 3.7.1, attackers could delete your hosted files without permission by guessing the delete_code tokens. This could lead to data loss or unauthorized content removal from your instance.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by enabling unauthorized deletion of sensitive files, potentially leading to data breaches or loss of protected data integrity. Compliance may require immediate patching to prevent unauthorized access.

Mitigation Strategies

Immediately upgrade PictShare to version 3.7.1 or later to fix the weak randomness issue. If upgrading is not possible, replace the rand() function with a cryptographically secure random number generator like random_int() in PHP. Review and restrict file deletion permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104356. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart