ExploitMatch
Back

CVE-2026-88837

Monitor on ThreatCluster

Description

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.