Description
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."
Published: 2026-10-04
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Weak Password Hash
Action: Immediate Mitigation
AI Analysis

Impact

A weakness in YzmCMS's MD5 password handler allows manipulation of the password argument to produce a hash with insufficient computational effort. An attacker can launch this attack remotely, though it requires high complexity and is considered difficult to exploit. The effect is that attackers can more easily derive the original password, leading to potential unauthorized system access.

Affected Systems

YzmCMS versions up to and including 7.6 are affected. No patch has been released yet; the vendor plans a new release in March 2027 that will support gradual migration to stronger hashing algorithms.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Because the hash uses MD5 and is weak, this is inferred to make offline brute‑force easier, but the attack requires remote manipulation and is considered difficult, so the likelihood of exploitation is moderate.

Generated by OpenCVE AI on October 4, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YzmCMS to a version that employs a stronger password hash such as bcrypt or Argon2 and that includes gradual migration; if the upgrade is unavailable, wait for the March 2027 release.
  • Apply the vendor’s published security mitigation guidance to disable MD5 hashing and enforce stronger password policies, including length, complexity, and lockout after repeated failures.
  • Limit access to password‑handling endpoints, monitor authentication logs for anomalous activity, and consider using proactive intrusion detection to detect brute‑force attempts.

Generated by OpenCVE AI on October 4, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."
Title YzmCMS MD5 system.func.php password weak password hash
First Time appeared Yzmcms
Yzmcms yzmcms
Weaknesses CWE-326
CWE-916
CPEs cpe:2.3:a:yzmcms:yzmcms:*:*:*:*:*:*:*:*
Vendors & Products Yzmcms
Yzmcms yzmcms
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T12:30:10.845Z

Reserved: 2026-10-03T19:27:13.617Z

Link: CVE-2026-105156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T15:16:30.050

Modified: 2026-10-04T15:16:30.050

Link: CVE-2026-105156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T19:00:13Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength

  • CWE-916

    Use of Password Hash With Insufficient Computational Effort