
🚨 HIGH - Weak credential hashing exposes superadmin password recovery (CVE-2026-41879) R-SOFT DMS stores the superadmin credential as a non-salted nested MD5 hash in its configuration, making the stored password hash a recoverable secret. The root cause is use of broken cryptography and improper credential storage (unsalted MD5), enabling efficient offline cracking and rainbow-table style attacks. An attacker exploits this by first obtaining the stored hash (e.g., config file read via file disclosure, backup leak, or local access) and then cracking it offline to recover the superadmin password, which is especially dangerous because the password can’t be rotated via the UI. Successful exploitation results in full superadmin account compromise with administrative control over the DMS instance and potential data access, tampering, and service takeover. 👉 Affected: R-SOFT DMS versions prior to v3.17-2000 | Upgrade to v3.17-2000
Post summary
The advisory reveals that CVE‑2026‑41879 allows offline cracking of the superadmin password due to unsalted MD5 hashing, enabling full administrative compromise, and recommends upgrading to v3.17‑2000.
