CVE-2026-107612
Last modified
CVE-2026-107612 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity.
Description
Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity. A low-privileged local process can open the mapping and tamper with the IPC channel of a service running as SYSTEM, potentially leading to disclosure of session data, privilege escalation, or denial of service.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| GlavSoft | TightVNC | < 2.8.88 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107612?
How severe is CVE-2026-107612?
How do I fix CVE-2026-107612?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107587Improper certificate validation in the webmail of Progressiv…5.9
- CVE-2026-107589Insufficient job validation for service accounts in Jacamar …7.5
- CVE-2026-1076The Star Review Manager plugin for WordPress is vulnerable t…4.3
- CVE-2026-107604A flaw was found in the installation provider and client reg…4.9
- CVE-2026-107608Improper link resolution before file access in the asset bun…5.5
- CVE-2026-107611An out-of-bounds read vulnerability in the ZRLE decoder of G…7.1
- CVE-2026-107613A NULL pointer dereference vulnerability in the Win8ScreenDr…5.9
- CVE-2026-107614An integer underflow in WinCursorShapeUtils::trimTransparent…6.1
- CVE-2026-107615An uncontrolled search path element vulnerability in GlavSof…7.8
- CVE-2026-107623A flaw was found in the OIDC Dynamic Client Registration (DC…4.3
- CVE-2026-10763PROMOD V is using insecure HTTP communication instead of HTT…7
- CVE-2026-107634Dislocker through 0.7.3 contains a heap out-of-bounds read v…6.1
Are you affected by CVE-2026-107612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
