Weak Hash Vulnerability in Open Source Point of Sale by opensourcepos
CVE-2026-8803

6.3MEDIUM

Key Information:

Vendor
CVE Published:
18 May 2026

What is CVE-2026-8803?

A vulnerability has been identified in the Employee Login function of Open Source Point of Sale up to version 3.4.2. The flaw resides in the use of a weak hashing mechanism within the login process, specifically in the app/Models/Employee.php file. This could lead to potential remote exploitation, allowing attackers to gain unauthorized access. Although the mechanism has been implemented, it presents challenges as the weak hash is only used initially and is not actively in play for password changes. As the vendor notes, there exists code that supports legacy hash functions to ensure upgrade compatibility, though efforts are expected to phase this out in future releases.

Affected Version(s)

Open Source Point of Sale 3.4.0

Open Source Point of Sale 3.4.1

Open Source Point of Sale 3.4.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamran Saifullah (VulDB User)
VulDB CNA Team
.