{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pictshare--2.0.0--3.7.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.9,"id":"CVE-2026-104356"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PictShare (\u003e= 2.0.0 \u003c 3.7.1)"],"_cs_severities":["low"],"_cs_tags":["web-application-vulnerability","cve-2026-104356","pictshare"],"_cs_type":"advisory","_cs_vendors":["HaschekSolutions"],"content_html":"\u003cp\u003ePictShare, a self-hosted image and media hosting platform, is vulnerable to an unauthorized file deletion issue identified as CVE-2026-104356. The vulnerability stems from the use of PHP's non-cryptographic \u003ccode\u003erand()\u003c/code\u003e function within the \u003ccode\u003egetRandomString()\u003c/code\u003e method to generate the \u003ccode\u003edelete_code\u003c/code\u003e authorization token. Because the generator state is linked to the publicly accessible file hash found in each shared URL, the sequence of generated codes is predictable. An attacker can determine the deletion token for any hosted image without needing to access the administrative information endpoint. This allows remote attackers to delete images from the server without authorization. The issue was disclosed on October 1, 2026, and addressed in version 3.7.1. Notably, files uploaded prior to the patch remain vulnerable until they are re-uploaded, as existing delete codes were not automatically rotated.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target instance of PictShare running a version prior to 3.7.1.\u003c/li\u003e\n\u003cli\u003eAttacker visits a public image URL to obtain the associated public file hash, which serves as a seed for the non-cryptographic PRNG.\u003c/li\u003e\n\u003cli\u003eAttacker uses the PRNG state derived from the public hash to calculate the corresponding \u003ccode\u003edelete_code\u003c/code\u003e token generated by the vulnerable \u003ccode\u003egetRandomString()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a HTTP request targeted at the PictShare deletion endpoint, embedding the calculated \u003ccode\u003edelete_code\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application receives the request, treats the forged token as valid, and initiates the file deletion process.\u003c/li\u003e\n\u003cli\u003eThe targeted file is removed from the server, resulting in unauthorized data destruction.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to delete any file hosted on a vulnerable PictShare instance. This facilitates unauthorized data loss and potential disruption of service for users of the self-hosted media platform. Because existing delete codes are not rotated after patching, legacy data remains at risk until administrators take manual action or files are re-uploaded.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all PictShare instances to version 3.7.1 or later to remediate CVE-2026-104356. Organizations should scan their storage for assets uploaded prior to the patch and consider manual re-uploads or code rotation to invalidate the legacy predictable tokens. Monitor web server logs for high-frequency POST requests to deletion-related endpoints originating from single IP addresses, which may indicate automated token brute-forcing or mass-deletion attempts.\u003c/p\u003e\n","date_modified":"2026-10-02T11:34:25Z","date_published":"2026-10-02T11:34:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pictshare-predictable-delete-code/","summary":"PictShare versions prior to 3.7.1 contain a vulnerability where insecure PRNG usage for delete_code generation allows unauthenticated attackers to delete arbitrary files from hosted instances.","title":"Unauthorized File Deletion in PictShare via Predictable Delete Codes","url":"https://feed.craftedsignal.io/briefs/2026-10-pictshare-predictable-delete-code/"}],"language":"en","title":"CraftedSignal Threat Feed - PictShare (\u003e= 2.0.0 \u003c 3.7.1)","version":"https://jsonfeed.org/version/1.1"}