[PictShare]( generates the `delete_code`
authorization token with `getRandomString()`, which draws every character from PHP's
non-cryptographic `rand()`. Because `rand()` is not a CSPRNG — and the **same generator**
produces the public file hash shown in every shared URL — the `delete_code` is predictable
rather than secret, allowing unauthorized deletion of hosted files without ever reading the
| **CVE** | [CVE-2026-104356]( |
| **Product** | PictShare (self-hosted image/media host) |
| **Affected** | `>= 2.0.0`, ` Note: delete codes issued **before** the fix are not rotated, so pre-fix uploads remain
| 2026-10-01 | Public disclosure, CVE reserved & published (VulnCheck), fixed in v3.7.1 |
Responsibly disclosed to the vendor and coordinated through VulnCheck. Fixed before this
PoC was released. Published for defensive and educational purposes.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
