CVE-2026-56016

MEDIUM

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-56016. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-56016, a vulnerability in CGI::Session::ID::md5 (Perl) versions before 4.49 that generates predictable session IDs from low-entropy sources. The module includes placeholder code with no functional exploit implementation, only connection checks and TODO warnings.

Description

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a small range, the epoch time can be guessed or read from the HTTP Date header, and Perl's rand() is unsuitable for security purposes because it is predictable and reversible. An attacker who predicts a session id can impersonate the corresponding session and bypass authentication.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-56016_cgisessionidmd5_versions_before.py

This repository contains an auto-generated stub module for CVE-2026-56016, a vulnerability in CGI::Session::ID::md5 (Perl) versions before 4.49 that generates predictable session IDs from low-entropy sources. The module includes placeholder code with no functional exploit implementation, only connection checks and TODO warnings.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: CGI::Session::ID::md5 (Perl) versions before 4.49
No auth needed
Prerequisites: Target must be running a vulnerable version of CGI::Session::ID::md5 (<4.49) · Network access to the target service
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 5.9
EPSS 0.0036
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-338 CWE-340
Status published
Products (1)
MARKSTOS/CGI::Session::ID::md5 < 4.49
Published Jul 01, 2026
Tracked Since Jul 01, 2026