CVE-2026-41879Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-328

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Weak credential hashing exposes superadmin password recovery (CVE-2026-41879) R-SOFT DMS stores the superadmin credential as a non-salted nested MD5 hash in its configuration, making the stored password hash a recoverable secret. The root cause is use of broken cryptography and improper credential storage (unsalted MD5), enabling efficient offline cracking and rainbow-table style attacks. An attacker exploits this by first obtaining the stored hash (e.g., config file read via file disclosure, backup leak, or local access) and then cracking it offline to recover the superadmin password, which is especially dangerous because the password can’t be rotated via the UI. Successful exploitation results in full superadmin account compromise with administrative control over the DMS instance and potential data access, tampering, and service takeover. 👉 Affected: R-SOFT DMS versions prior to v3.17-2000 | Upgrade to v3.17-2000

    Post summary

    The advisory reveals that CVE‑2026‑41879 allows offline cracking of the superadmin password due to unsalted MD5 hashing, enabling full administrative compromise, and recommends upgrading to v3.17‑2000.

    0000097
    246 followersView on X

Explore more