CVE-2026-18397
9.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Thales | SConnect | 0 < 2.16.1.0 | affected |
Weaknesses
- CWE-347: CWE-347 Improper verification of cryptographic signature
- CWE-130: CWE-130 Improper handling of length parameter inconsistency
- CWE-457: CWE-457 Use of uninitialized variable
- CWE-252: CWE-252 Unchecked return value
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.