Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
Improper access control in Hashtopolis server chunk activity component
CVE-2026-22104
Description
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.
Affected products
1- Range: <0.14.8
Patches
Vulnerability mechanics
References
3- csirt.divd.nl/CVE-2026-22104mitrethird-party-advisory
- csirt.divd.nl/DIVD-2026-00010mitrethird-party-advisory
- github.com/hashtopolis/server/releases/tag/v0.14.8mitrevendor-advisory
News mentions
0No linked articles in our index yet.