<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Lsencrypt (2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/lsencrypt-2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 06 Sep 2026 09:49:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/lsencrypt-2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Lansweeper lsrunase and lsencrypt Password Recovery Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-39031-lansweeper/</link><pubDate>Sun, 06 Sep 2026 09:49:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-39031-lansweeper/</guid><description>CVE-2026-39031 is a critical credential security flaw in Lansweeper lsrunase 2.0 and lsencrypt 2.0 that allows attackers to perform offline decryption of stored passwords.</description><content:encoded><![CDATA[<p>CVE-2026-39031 identifies a severe cryptographic design flaw in Lansweeper's lsrunase 2.0 and lsencrypt 2.0 tools. The software utilizes a reversible RC4-based encryption scheme to store credentials, relying on a static 142-byte suffix hardcoded within the binary and an 8-character plaintext prefix stored alongside the ciphertext.</p>
<p>Because the encryption process does not utilize per-installation or per-user secrets and uses a predictable key derivation process (SHA-1 over the hardcoded suffix and the plaintext prefix), any attacker with local access to the encrypted password strings can trivially recover the plaintext credentials offline. This vulnerability allows for unauthorized password recovery without any brute-force requirements, directly exposing administrative credentials, facilitating lateral movement, and enabling the retroactive decryption of previously captured or backed-up password strings.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows local attackers to decrypt stored credentials managed by Lansweeper tools. This compromise can lead to full privilege escalation if the recovered credentials have administrative rights, and enables lateral movement across the network where those accounts are authorized. Given the prevalence of these tools in administrative environments, this vulnerability significantly increases the risk of credential harvesting and identity-based attacks.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all systems running Lansweeper lsrunase 2.0 or lsencrypt 2.0.</li>
<li>Implement strict access controls to the configuration files or registry keys where these encrypted strings are stored to prevent unauthorized access by local users.</li>
<li>Rotate all credentials that were previously stored using these versions of lsrunase or lsencrypt.</li>
<li>Migrate away from these legacy tools to modern, secure credential management solutions that support strong, non-reversible encryption standards.</li>
<li>Monitor file access events for the configuration locations of these specific tools to identify potential harvesting attempts.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>cve-2026-39031</category><category>credential-theft</category><category>cryptography</category></item></channel></rss>