CVE-2026-25726Patch(cloudreve / cloudreve)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cloudreve cloudreve systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. These secrets are generated upon first startup and persisted in the database. An attacker can exploit this by obtaining the administrator's account creation time (via public API endpoints) to narrow the search window for the PRNG seed, and use known hashid to validate the seed. By brute-forcing the seed (demonstrated to take <3 hours on general consumer PC), an attacker can predict the secret_key. This allows them to forge valid JSON Web Tokens (JWTs) for any user, including administrators, leading to full account takeover and privilege escalation. This issue has been patched in version 4.13.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudreve

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cloudreve

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-01: 1Mentions · 2026-04-04: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-04: 104-0104-04
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-011
Patch1
2026-04-041
Disclosure1
Full discourse2 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🔐 CVE-2026-25726 (Cloudreve): High account takeover via weak PRNG token seeding. Patch: Cloudreve update https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-25726 https://cloudreve.org/security

    Post summary

    CVE-2026-25726 exposes a high‑severity account takeover flaw in Cloudreve due to weak PRNG token seeding; a patch update for the application is available.

    100009
    492 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25726 - High Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with http://time.Now().UnixNano(... https://www.thehackerwire.com/vulnerability/CVE-2026-25726/ https://t.co/XjoqPWxOyt

    Post summary

    The post announces the CVE‑2026‑25726 vulnerability in Cloudreve, detailing the weak PRNG seeding that leads to potential exposure, but does not provide exploitation code, active attack evidence, or patch information.

    0000065
    164 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudrevecloudreve---

Explore more