#VU125827 Generation of Predictable Numbers or Identifiers in DotNetNuke - CVE-2026-40306
Published: April 11, 2026
DotNetNuke
DNN
Description
The vulnerability allows a remote attacker to bypass host identity assumptions.
The vulnerability exists due to the use of a hardcoded or non-unique identifier in HostGUID generation in the HostGUID installation logic when creating a new installation. A remote attacker can rely on the predictable HostGUID value to bypass host identity assumptions.
Only new installations are affected; upgrades from 9.x.x are not affected.