CVE-2026-105156
Received Received - Intake

Weak MD5 Password Hashing in YzmCMS

Vulnerability report for CVE-2026-105156, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yzmcms yzmcms to 7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects YzmCMS versions up to 7.6. The password() function in /common/function/system.func.php uses a double MD5 hashing scheme without salt to store passwords. This makes passwords vulnerable to rainbow table attacks and brute-force cracking. The function trims the password, applies MD5, takes a 26-character substring, and hashes it again with MD5. MD5 is cryptographically broken and lacks salt, providing no real security benefit.

Detection Guidance

Check if your YzmCMS version is up to 7.6 or lower by inspecting the file /common/function/system.func.php for the password() function. Look for double MD5 hashing without salt in lines 942-944. Search for files like admin_manage.class.php, index.class.php, and reset.php that may use this vulnerable function.

Impact Analysis

If an attacker gains access to the database, they can crack passwords instantly using rainbow tables or brute-force methods. This could lead to account takeover, privilege escalation, and unauthorized access to admin accounts. The exploit has been made public and is characterized by high complexity but is still a significant risk.

Compliance Impact

This vulnerability likely violates compliance requirements for secure password storage under GDPR and HIPAA, as it uses weak cryptographic hashing (MD5) without salt. Regulations require strong, salted hashing mechanisms to protect user credentials. Non-compliance could result in legal penalties and reputational damage.

Mitigation Strategies

Replace MD5 hashing with modern algorithms like bcrypt using PHP's password_hash() and password_verify(). Implement a migration strategy to rehash existing passwords when users log in. Monitor vendor updates for security mitigation guidance until the next release in March 2027.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105156. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart