Weak Randomness Vulnerability in PictShare by Haschek Solutions
CVE-2026-104356
8.2HIGH
What is CVE-2026-104356?
PictShare prior to version 3.7.1 suffers from a weak randomness issue stemming from its use of the non-cryptographic rand() PRNG in the getRandomString() function. This vulnerability compromises the security of authorization tokens, specifically the delete_code used for file deletion. Attackers can predict the PRNG state, enabling them to craft valid delete_code tokens and execute unauthorized deletions of hosted files, even without access to the underlying code via the info endpoint.
Affected Version(s)
pictshare 2.0.0 < 3.7.1
