Description
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.
References (1)
Core 1
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-41876
Scores
CVSS v4
8.2
EPSS
0.0020
EPSS Percentile
10.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-328
Status
published
Products (1)
R-SOFT SERWIS/DMS
< v3.17-2000
Published
Jul 10, 2026
Tracked Since
Jul 10, 2026