SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.
References
Configurations
No configuration.
History
17 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/chaitin/SafeLine/issues/1298 - |
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 14:17
NVD link : CVE-2026-92749
Mitre link : CVE-2026-92749
CVE.ORG link : CVE-2026-92749
JSON object : View
Products Affected
No product.
CWE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
