---
id: CVE-2026-104356
title: >-
  PictShare before version 3.7.1 contains a weak randomness vulnerability where
  the getRandomString() function uses the non-cryptographic rand() PRNG to
  generate the delete_code authorization token in src/inc/core.php
summary: >-
  PictShare before version 3.7.1 contains a weak randomness vulnerability where
  the getRandomString() function uses the non-cryptographic rand() PRNG to
  generate the delete_code authorization token in src/inc/core.php. Attackers
  can predic…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-338
vendor: HaschekSolutions
product: pictshare
affected:
  - pictshare >= 2.0.0 < 3.7.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:00.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104356'
references:
  - url: >-
      https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3
    label: disclosure@vulncheck.com
  - url: 'https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pictshare-predictable-delete-code-via-rand
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T23:03:32.770Z'
---

## Overview

PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
