SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-57310

MEDIUM · CVSS 6.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Windu CMS employs a weak hashing algorithm based on MD5 and SHA1 with a static salt for storing user passwords, making it susceptible to credential decoding if an attacker gains access to the password hashes. Organizations using version 4.1 or potentially other versions of Windu CMS should prioritize addressing this vulnerability to protect user credentials and mitigate the risk of unauthorized access.

CVE
CVE-2026-57310
Severity
MEDIUM
CVSS
6.3
EPSS
0.17%

Original NVD Description

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.