๐Ÿ” CVE Alert

CVE-2026-104356

MEDIUM 5.9

PictShare < 3.7.1 Predictable Delete Code via rand()

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.

CWE CWE-338
Vendor hascheksolutions
Product pictshare
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for hascheksolutions pictshare

Be the first to know when new medium vulnerabilities affecting hascheksolutions pictshare are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

HaschekSolutions / pictshare
2.0.0 < 3.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3 github.com: https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1 vulncheck.com: https://www.vulncheck.com/advisories/pictshare-predictable-delete-code-via-rand

Credits

Alisher Qarshibayev VulnCheck