Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • October 2, 2026

[PictShare]( generates the `delete_code`

authorization token with `getRandomString()`, which draws every character from PHP's

non-cryptographic `rand()`. Because `rand()` is not a CSPRNG — and the **same generator**

produces the public file hash shown in every shared URL — the `delete_code` is predictable

rather than secret, allowing unauthorized deletion of hosted files without ever reading the

| **CVE** | [CVE-2026-104356]( |

| **Product** | PictShare (self-hosted image/media host) |

| **Affected** | `>= 2.0.0`, ` Note: delete codes issued **before** the fix are not rotated, so pre-fix uploads remain

| 2026-10-01 | Public disclosure, CVE reserved & published (VulnCheck), fixed in v3.7.1 |

Responsibly disclosed to the vendor and coordinated through VulnCheck. Fixed before this

PoC was released. Published for defensive and educational purposes.

Extracted Entities

Attack Types (1)

Platforms (1)