SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-22104

HIGH · CVSS 7.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Hashtopolis server web-interface prior to version 0.14.8 has an improper access control vulnerability that permits any user account to access all cracked hashes within the server instance. This exposure could lead to unauthorized disclosure of sensitive data, potentially compromising the security of password hashes. Organizations using affected versions should prioritize this issue to prevent unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-22104
Severity
HIGH
CVSS
7.1
EPSS
0.32%

Original NVD Description

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.