Account takeover via loose MD5 comparison
Published Feb 19, 2026 · Updated Feb 19, 2026
Authentication bypass in Open Game Panel OGP-Website before commit 52f865a allows remote attackers to access accounts via crafted passwords. The login and API-token paths in index.php and ogp_api.php use PHP's loose equality operator to compare attacker-controlled MD5 results with stored password hashes. Exploitation requires a known username whose stored MD5 hash has numeric 0e form; success grants that account's web session or API token.
Summary
What happened
Authentication bypass in Open Game Panel OGP-Website before commit 52f865a allows remote attackers to access accounts via crafted passwords. The login and API-token paths in index.php and ogp_api.php use PHP's loose equality operator to compare attacker-controlled MD5 results with stored password hashes. Exploitation requires a known username whose stored MD5 hash has numeric 0e form; success grants that account's web session or API token.
The record
- CVE
- CVE-2025-15586
- Published
- Feb 19, 2026
- Updated
- Feb 19, 2026
- Vendor
- Open Game Panel
- Product
- OGP-Website
- Classifications
- CWE-287, CAPEC-115, T1078
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Feb 19, 2026CVE publishedPublication date reported by the CVE source.
- Feb 19, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=52f865a4fba763594453068acf8fa9e3fc38d663
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- OGP-Website magic-hash authentication-bypass demonstrationproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo