CVE-2026-22104: Hashtopolis Server

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.

Affected products

Published 2026-07-17. Last modified 2026-07-17.