Vulnerability Description
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2026-22104
- https://csirt.divd.nl/DIVD-2026-00010
- https://github.com/hashtopolis/server/releases/tag/v0.14.8
FAQ
What is CVE-2026-22104?
CVE-2026-22104 is a documented vulnerability. Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance...
How severe is CVE-2026-22104?
CVSS scoring is not yet available for CVE-2026-22104. Check NVD for updates.
Is there a patch for CVE-2026-22104?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.