CVE-2026-92749

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.
Configurations

No configuration.

History

17 Sep 2026, 14:17

Type Values Removed Values Added
References () https://github.com/chaitin/SafeLine/issues/1298 - () https://github.com/chaitin/SafeLine/issues/1298 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 14:17


NVD link : CVE-2026-92749

Mitre link : CVE-2026-92749

CVE.ORG link : CVE-2026-92749


JSON object : View

Products Affected

No product.

CWE
CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)