CVE-2026-25726 impacts Cloudreve, a self-hosted file management and sharing system, prior to version 4.13.0, due to its use of a weak pseudo-random number generator for critical security secrets like secret_key. An attacker can exploit this by obtaining an administrator's account creation time and brute-forcing the PRNG seed, which has been demonstrated to take less than three hours on a consumer PC, indicating a high attack complexity. This allows the attacker to predict the secret_key, forge valid JSON Web Tokens (JWTs) for any user, including administrators, leading to full account takeover and privilege escalation, reflected in its CVSS score of 8.1 (High). While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.13.0CPE matchmatch criteria | cpe:2.3:a:cloudreve:cloudreve:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.