CVE-2026-92749 PUBLISHED

SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor chaitin
Product SafeLine
Versions Default: unaffected
  • affected from 0 to 9.4.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CWE