Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92749— SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret

Quick assessment

Affected
chaitin SafeLine
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SafeLine 9.4.1 及更早版本从基于时间种子的 math/rand 随机数生成器派生管理控制台的会话签名密钥,使得攻击者可以在离线环境中重建该密钥。能够限定安装时间戳的未认证远程攻击者可以重新生成该密钥,并伪造有效的管理员会话 Cookie,从而获取对受保护站点的控制权。

CVSS 8.1 · High EPSS 0.52% · P43

Possible ATT&CK Techniques 1 AI

T1550 · Use Alternate Authentication Material

Affected Version Matrix 1

VendorProduct Version RangeStatus
chaitin SafeLine ≤ 9.4.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92749

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret
Source: CVE Program / CVE List V5
Vulnerability Description
SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
chaitin SafeLine 0 ~ 9.4.1 -

II. Public POCs for CVE-2026-92749

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92749

登录查看更多情报信息。

Other References for CVE-2026-92749 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92749

No comments yet


Leave a comment