THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86187 (MEDIUM 5.9) — WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted M

[NVD] CVE-2026-86187 (MEDIUM 5.9) — WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted M

mednvdPublished 2026-09-05

CVE-2026-86187 CVSS: 5.9 MEDIUM Published: 2026-09-05T13:18:13.703

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86187