Skip to content
Threat Feed
low advisory

Unauthorized File Deletion in PictShare via Predictable Delete Codes

PictShare versions prior to 3.7.1 contain a vulnerability where insecure PRNG usage for delete_code generation allows unauthenticated attackers to delete arbitrary files from hosted instances.

CVE search metadata

CVE search record: CVE-2026-104356. Severity: medium. CVSS: 5.9. KEV: no. Product: PictShare (>= 2.0.0 < 3.7.1). Brief: Unauthorized File Deletion in PictShare via Predictable Delete Codes. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pictshare-predictable-delete-code/

PictShare, a self-hosted image and media hosting platform, is vulnerable to an unauthorized file deletion issue identified as CVE-2026-104356. The vulnerability stems from the use of PHP's non-cryptographic rand() function within the getRandomString() method to generate the delete_code authorization token. Because the generator state is linked to the publicly accessible file hash found in each shared URL, the sequence of generated codes is predictable. An attacker can determine the deletion token for any hosted image without needing to access the administrative information endpoint. This allows remote attackers to delete images from the server without authorization. The issue was disclosed on October 1, 2026, and addressed in version 3.7.1. Notably, files uploaded prior to the patch remain vulnerable until they are re-uploaded, as existing delete codes were not automatically rotated.

Attack Chain

  1. Attacker identifies a target instance of PictShare running a version prior to 3.7.1.
  2. Attacker visits a public image URL to obtain the associated public file hash, which serves as a seed for the non-cryptographic PRNG.
  3. Attacker uses the PRNG state derived from the public hash to calculate the corresponding delete_code token generated by the vulnerable getRandomString() function.
  4. Attacker constructs a HTTP request targeted at the PictShare deletion endpoint, embedding the calculated delete_code.
  5. The application receives the request, treats the forged token as valid, and initiates the file deletion process.
  6. The targeted file is removed from the server, resulting in unauthorized data destruction.

Impact

Successful exploitation allows unauthenticated attackers to delete any file hosted on a vulnerable PictShare instance. This facilitates unauthorized data loss and potential disruption of service for users of the self-hosted media platform. Because existing delete codes are not rotated after patching, legacy data remains at risk until administrators take manual action or files are re-uploaded.

Recommendation

Prioritize the upgrade of all PictShare instances to version 3.7.1 or later to remediate CVE-2026-104356. Organizations should scan their storage for assets uploaded prior to the patch and consider manual re-uploads or code rotation to invalidate the legacy predictable tokens. Monitor web server logs for high-frequency POST requests to deletion-related endpoints originating from single IP addresses, which may indicate automated token brute-forcing or mass-deletion attempts.


Immediate actions

Upgrade all PictShare instances to version 3.7.1 or later

IT Operations 48h

Mitigations

Upgrade PictShare to v3.7.1

immediate IT Operations

CVE-2026-104356