CVE-2026-105156: YzmCMS MD5 system.func.php password weak password hash
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
YzmCMS versions up to 7.6 are affected, specifically the Password function in /common/function/system.func.php that handles MD5 password hashes.
What does an attacker need to exploit this issue?
The attack can be launched remotely without privileges or user interaction, but it requires high complexity. Public exploit information is available, although exploitability is assessed as difficult.
Is a vendor fix currently available?
The vendor states that a backward-compatible gradual hash migration feature is planned for the next scheduled release in March 2027. No earlier fixed version is identified in the available information.
What can organizations do before the planned release?
The vendor says it will publish security mitigation guidance in its official documentation for existing deployers before the new version is available. The provided information does not specify the mitigation steps.