CVE-2026-19896Disclosure

LOWCVSS 2.9 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-310CWE-330

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-09-08: 2PoC Mentioned / Linked · 2026-09-08: 1Technical Details · 2026-08-15: 2Technical Details · 2026-09-08: 208-1509-08
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-09-082
Disclosure1PoC1
Full discourse4 posts
  • Geng Yang@geng_zast
    PoC

    D-Tale's Flask SECRET_KEY looks random. It isn't random enough — and that's enough to forge a session. CVE-2026-19896: the key is 10 chars from A–Z0–9 via numpy.random → ~2^51.7 space. A GPU cluster recovers it offline in ~2.1 days. Then you forge {"logged_in":true,"username":"admin"}.

    Post summary

    The post demonstrates a proof‑of‑concept for forging a session by cracking a low‑entropy Flask SECRET_KEY, but it doesn’t commit to a full exploit, active use, or available patch.

    1002069
    48 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    https://ZAST.AI verified two CVEs in D-Tale ≤ 3.22.0 (CVSS 3.1 = 6.5), both in auth when enabled. CVE-2026-19896: Flask SECRET_KEY from numpy.random (~2^51.7) → offline recovery + session forgery. https://t.co/WoN0lzmhee

    Post summary

    The tweet announces that two CVEs in D‑Tale (≤3.22.0) have been verified, providing technical details for CVE‑2026‑19896 related to Flask’s SECRET_KEY generation and resulting in offline recovery and session forgery.

    20001125
    39 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19896 A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session… https://www.cve.org/CVERecord?id=CVE-2026-19896 ----- Traducción: Se ha encontrado u… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑19896, a flaw in mangroup dtale’s build_secret_key function affecting Flask Session, without providing any PoC, exploit, or patch details.

    0000038
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19896 A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session… https://www.cve.org/CVERecord?id=CVE-2026-19896

    Post summary

    A flaw in mangroup dtale’s Flask Session build_secret_key function has been disclosed, but no Proof of Concept, exploit, or mitigation is mentioned.

    000001.1K
    57.9K followersView on X

Explore more