CVE-2026-41526

1 karet z 1 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-41526

EPSS 0.00

Hodnocení závažnosti

6.5 CVSS 3.1 mitre

útok z místního přístupu útok vyžaduje přípravu bez přihlášení nutný zásah uživatele
dopad plný únik dat úplná změna dat částečný výpadek
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.

Information published.

EPSS 0.00 CVE-2026-41526 KDE US

Microsoft Security ·