CVE-2026-41879CWE-328

Weak password hashing in R-SOFT DMS

High · published July 10, 2026

CVSS v4.0
8.2
EPSS
0%
Percentile
18.8
In the wild
Unconfirmed
What it is

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

This issue was fixed in version v3.17-2000.

The record
Technical detail
CVSS v4.0
8.2 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00269 · 18.8th percentile
Weakness
CWE-328 · Use of Weak Hash
Published
2026-07-10T09:05Z
EPSS history
Timeline
  • 10 JUL 09:05Z
    Weak password hashing in R-SOFT DMS
    cvelistv5