Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
Weak password hashing in R-SOFT DMS
CVE-2026-41879
Description
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.
This issue was fixed in version v3.17-2000.
Affected products
1Patches
Vulnerability mechanics
References
1- cert.pl/posts/2026/07/CVE-2026-41876mitrethird-party-advisory
News mentions
0No linked articles in our index yet.