Unauthorized File Deletion in PictShare via Predictable Delete Codes
PictShare versions prior to 3.7.1 contain a vulnerability where insecure PRNG usage for delete_code generation allows unauthenticated attackers to delete arbitrary files from hosted instances.
CVE search metadata
CVE search record: CVE-2026-104356. Severity: medium. CVSS: 5.9. KEV: no. Product: PictShare (>= 2.0.0 < 3.7.1). Brief: Unauthorized File Deletion in PictShare via Predictable Delete Codes. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pictshare-predictable-delete-code/
PictShare, a self-hosted image and media hosting platform, is vulnerable to an unauthorized file deletion issue identified as CVE-2026-104356. The vulnerability stems from the use of PHP's non-cryptographic rand() function within the getRandomString() method to generate the delete_code authorization token. Because the generator state is linked to the publicly accessible file hash found in each shared URL, the sequence of generated codes is predictable. An attacker can determine the deletion token for any hosted image without needing to access the administrative information endpoint. This allows remote attackers to delete images from the server without authorization. The issue was disclosed on October 1, 2026, and addressed in version 3.7.1. Notably, files uploaded prior to the patch remain vulnerable until they are re-uploaded, as existing delete codes were not automatically rotated.
Attack Chain
- Attacker identifies a target instance of PictShare running a version prior to 3.7.1.
- Attacker visits a public image URL to obtain the associated public file hash, which serves as a seed for the non-cryptographic PRNG.
- Attacker uses the PRNG state derived from the public hash to calculate the corresponding
delete_codetoken generated by the vulnerablegetRandomString()function. - Attacker constructs a HTTP request targeted at the PictShare deletion endpoint, embedding the calculated
delete_code. - The application receives the request, treats the forged token as valid, and initiates the file deletion process.
- The targeted file is removed from the server, resulting in unauthorized data destruction.
Impact
Successful exploitation allows unauthenticated attackers to delete any file hosted on a vulnerable PictShare instance. This facilitates unauthorized data loss and potential disruption of service for users of the self-hosted media platform. Because existing delete codes are not rotated after patching, legacy data remains at risk until administrators take manual action or files are re-uploaded.
Recommendation
Prioritize the upgrade of all PictShare instances to version 3.7.1 or later to remediate CVE-2026-104356. Organizations should scan their storage for assets uploaded prior to the patch and consider manual re-uploads or code rotation to invalidate the legacy predictable tokens. Monitor web server logs for high-frequency POST requests to deletion-related endpoints originating from single IP addresses, which may indicate automated token brute-forcing or mass-deletion attempts.
Immediate actions
Upgrade all PictShare instances to version 3.7.1 or later
Mitigations
Upgrade PictShare to v3.7.1
CVE-2026-104356