Sceawere
Vulnerability Detail
CVE-2026-104356UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PictShare Weak PRNG Token Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 1d ago
- Vendor
- HaschekSolutions
- Product
- pictshare
- Attack Type
- Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-01T22:17:00.990Z",
"pubdate": "2026-10-01T22:17:00.990Z",
"executiveSummary": "PictShare versions prior to 3.7.1 are susceptible to a cryptographic vulnerability involving the generation of file deletion tokens. The application utilizes the standard, non-cryptographic rand() function within the getRandomString() routine to produce the delete_code authorization token. Because the standard rand() function is not designed for security-sensitive operations and is inherently predictable, an attacker can analyze the PRNG output to infer the internal state. This vulnerability allows an unauthenticated remote attacker to predict valid delete_code values for hosted files. Successful exploitation enables unauthorized deletion of arbitrary files on the server, resulting in data loss and potential service disruption. The risk is significant as it requires no prior knowledge of the file metadata or the info endpoint, and the predictable nature of the PRNG state significantly lowers the barrier to entry for malicious actors seeking to perform unauthorized administrative actions against the file storage system.",
"technicalDetails": "The vulnerability resides in src/inc/core.php within the getRandomString() function, which is responsible for generating cryptographically sensitive authorization tokens, specifically the delete_code used to manage file removal. The implementation relies on the PHP rand() function, which is a libc-based pseudo-random number generator (PRNG) not suitable for security applications. The PRNG implementation in many environments uses a linear congruential generator or a Mersenne Twister, both of which are deterministic and provide insufficient entropy for security-sensitive tokens.\nThe attack flow involves observing a series of generated delete_code values to determine the PRNG's internal state. Since rand() often seeds based on predictable factors such as the current timestamp or process ID, an attacker can narrow down the potential seed space. By collecting a sufficient sample of previously generated tokens, an attacker can reconstruct the state of the PRNG. Once the state is modeled, the attacker can forecast future outputs of the getRandomString() function.\nExploitation occurs when the attacker forecasts the delete_code for a target file hosted on the PictShare instance. The attacker then constructs a request containing the predicted code to trigger the deletion logic within the application. Because the application trusts the delete_code as a valid authorization mechanism for file removal, the request is processed without further authentication. This process does not require access to the info endpoint or prior knowledge of the target file's unique identifier beyond the predicted token.\nThe impact is a total compromise of file integrity and availability. An attacker can systematically enumerate and delete all stored media, leading to permanent data loss. The vulnerability is present in the codebase prior to version 3.7.1 and is exposed via the network to any remote actor capable of interacting with the application's file management functions. The reliance on non-cryptographic randomness for access control constitutes a fundamental failure in security design, as the token generation process lacks the necessary cryptographic strength to withstand prediction-based analysis."
}