SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-41879

HIGH · CVSS 8.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

R-SOFT DMS is vulnerable due to its use of a non-salted nested MD5 hash for storing superadmin credentials, allowing attackers to easily decode these credentials if they obtain the password hash. The inability to change the password without modifying the configuration file exacerbates the risk, making it critical for organizations using this software to upgrade to version v3.17-2000 immediately to mitigate potential unauthorized access. System administrators and security teams should prioritize this vulnerability to protect sensitive administrative functions.

CVE
CVE-2026-41879
Severity
HIGH
CVSS
8.2
EPSS
0.20%

Original NVD Description

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.