CVE-2026-22104: Hashtopolis Server
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.
Affected products
- Hashtopolis Server: before 0.14.8 (fixed in 0.14.8)
Published 2026-07-17. Last modified 2026-07-17.