CVE-2026-8803General

LOWCVSS 6.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerability is currently in question. The vendor explains: "[T]he code is still there to allow the upgrade path to work. The default password is initially seeded with the old hash function, but then migrated to a newer one after login. [T]he hash version check might be cleaned up in the future. Currently it's not actively in use as any password change will use a newer hash function."

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327CWE-328

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-18); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Active Exploitation · 2026-05-19: 105-1805-19
Signal classification2 categories
General
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-182
General2
2026-05-191
Active Exploitation1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting opensourcepos Open Source Point of Sale (CVE-2026-8803) https://vuldb.com/vuln/364436/cti

    Post summary

    Offensive activities targeting the Open Source Point of Sale have been identified, indicating CVE-2026-8803 is actively exploited, although no PoC or exploit code details are provided.

    0000083
    2.2K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-8803 📊 Severity: 3.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-8803 #CVE-2026-8803 #CVE #Low  #CyberSecurity #InfoSec https://t.co/XipLeSm5wy

    Post summary

    The tweet simply announces CVE‑2026‑8803, noting its low severity (3.7) and that it affects multiple unspecified products, without providing technical details, exploit code, or patch information.

    0000053
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8803 Weak Hash Vulnerability in Open Source Point of Sale Employee Login Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8803

    Post summary

    The post merely references CVE‑2026‑8803 with a brief title and a link to a vulnerability database, offering no detailed technical, exploitation or mitigation information.

    0000055
    4.0K followersView on X

Explore more