CVE-2026-25861
MEDIUMDescription
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial.
Is your site exposed to CVE-2026-25861?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-25861? +
How severe is CVE-2026-25861? +
How do I check if I'm vulnerable to CVE-2026-25861? +
Related Vulnerabilities
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an …
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and …
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password …
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in …
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to …
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute …