CVE-2026-92921: admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5

Published Sep 17, 2026
·
Updated

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort.

Affected Software

1 affected component
admin3<=3.0.0

Event History

Sep 17, 2026
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this weakness?

An attacker needs access to the database containing account credential hashes. The attack is performed offline, allowing dictionary or brute-force attempts without interacting with the application.

2

What is the practical impact if the credential database is exposed?

Password hashes can be cracked with negligible computational effort because they use single-round MD5, the username as the only salt, and no key derivation function. Recovered plaintext passwords may also put other accounts at risk where users reused those passwords.

3

How can I determine whether my deployment is affected?

Deployments of admin3 through version 3.0.0 are affected. Inspect stored credential hashes and the password-handling implementation for single-round MD5 hashing with the username used as the salt.

4

What can be done while a remediation is not available?

Restrict and monitor database access, protect database backups and exports, and rotate passwords for potentially exposed accounts. Because password cracking can occur offline after database access, reducing database exposure is the key immediate control.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203