CVE-2026-105156: YzmCMS MD5 system.func.php password weak password hash

Published Oct 4, 2026
·
Updated

A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."

Affected Software

1 affected component
YzmCMS YzmCMS<=7.6

Event History

Oct 4, 2026
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

YzmCMS versions up to 7.6 are affected, specifically the Password function in /common/function/system.func.php that handles MD5 password hashes.

2

What does an attacker need to exploit this issue?

The attack can be launched remotely without privileges or user interaction, but it requires high complexity. Public exploit information is available, although exploitability is assessed as difficult.

3

Is a vendor fix currently available?

The vendor states that a backward-compatible gradual hash migration feature is planned for the next scheduled release in March 2027. No earlier fixed version is identified in the available information.

4

What can organizations do before the planned release?

The vendor says it will publish security mitigation guidance in its official documentation for existing deployers before the new version is available. The provided information does not specify the mitigation steps.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203