Description
PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.
Published: 2026-10-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Predictable deletion of files through weak random token
Action: Apply patch
AI Analysis

Impact

The vulnerability exists in PictShare versions before 3.7.1, where the delete_code used for authorizing file removals is produced by the non‑cryptographic rand() function. Because rand() is deterministic and easily replayable, attackers can predict or infer the current generator state and generate valid delete_code values, allowing them to delete arbitrary hosted files without accessing any other information. The exploit therefore results in unauthorized data loss for the affected account and can be performed remotely as part of the standard delete request flow.

Affected Systems

Customers running PictShare from HaschekSolutions, any version older than 3.7.1, are vulnerable. The product is identified by the CPE cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*.*

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be Remote over the network because the delete operation is performed through HTTP requests that do not require privileged access. The weakness is a cryptographic failure (CWE-338), making the token generation insecure. Exploitation requires only standard HTTP requests to the delete endpoint and a predictable PRNG state, so the likelihood of successful attacks is high if attackers can observe or guess the seed.

Generated by OpenCVE AI on October 1, 2026 at 22:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PictShare to version 3.7.1 or newer, which replaces rand() with a cryptographically secure random generator for delete_code. If an upgrade is not possible immediately, modify getRandomString() to use random_bytes().
  • Restrict delete operations by implementing rate limiting or requiring additional authentication beyond delete_code to reduce the chance of successful guessing.
  • Audit deletion logs for unusual patterns and alert on repeated delete attempts from the same source.

Generated by OpenCVE AI on October 1, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.
Title PictShare < 3.7.1 Predictable Delete Code via rand()
First Time appeared Hascheksolutions
Hascheksolutions pictshare
Weaknesses CWE-338
CPEs cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:*
Vendors & Products Hascheksolutions
Hascheksolutions pictshare
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hascheksolutions Pictshare
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T21:21:45.992Z

Reserved: 2026-10-01T20:48:03.271Z

Link: CVE-2026-104356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:00.990

Modified: 2026-10-01T22:17:00.990

Link: CVE-2026-104356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)