Executive brief
admin3 is a lightweight backend administration framework that uses a weak password hashing scheme (single-round MD5 with username as salt) to store user account credentials. An attacker who gains access to the application database can easily recover plaintext passwords through offline dictionary or brute-force attacks due to MD5's low computational cost and lack of key derivation functions.
Technical details
The vulnerability is a cryptographic weakness in password storage: admin3 uses MD5 hashing with only the username concatenated as salt (without separator) and no key derivation function or work factor. The hashing implementation also exhibits a non-canonical encoding defect (leading zeros dropped by BigInteger.toString(16)), causing roughly 6.25% of hashes to be incompatible with standard MD5 representations. An attacker with database access can perform offline password recovery attacks with negligible computational effort. The vulnerability affects versions through 3.0.0; patched versions use proper password hashing with appropriate salt and key derivation.
Affected products
- LinYuanyi admin3 through 3.0.0
Timeline
- 2026-09-17: disclosed: CVE-2026-92921 published on NVD