CVE-2026-8076 Details
Description
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed since 2012. This could allow an attacker to easily perform a brute-force attack against a user and gain access by trying different PINs without the account being locked. Successful exploitation of this vulnerability could result in unauthorized access to confidential configuration settings, compromising the security of the system.
A vulnerability exists in the CashDro 3 web administration panel, specifically in version 24.01.00.26, due to weak credential requirements. The platform permits the use of numeric PINs for user authentication, a feature maintained for compatibility with POS software integrations since 2012. This weakness could enable an attacker to conduct brute-force attacks to guess PINs, potentially leading to unauthorized access. Exploiting this vulnerability could allow access to sensitive configuration settings, thereby undermining the system's security.
Users can update to the latest version of CashDro 3, which supports alphanumeric PINs, to address this vulnerability. The currently supported version required for the update is 26.01.00.16, as previous versions have been removed from the distribution repository for security reasons.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CashDro 3 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | CVE Modified | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion