CVE-2026-7701
Last modified
CVE-2026-7701 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7701?
How severe is CVE-2026-7701?
How do I fix CVE-2026-7701?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77004A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impac…7.4
- CVE-2026-77005The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 d…9.6
- CVE-2026-77006The WebTotem Backups WordPress plugin before 1.1.0 does not …9.6
- CVE-2026-77007The HEL Online Classroom: AI-powered Online Classrooms WordP…7.5
- CVE-2026-77008The HEL Online Classroom: AI-powered Online Classrooms WordP…6.5
- CVE-2026-77009The WatchMan-Site7 WordPress plugin through 4.2.0 does not r…9.9
- CVE-2026-77010The HEL Online Classroom: AI-powered Online Classrooms WordP…6.5
- CVE-2026-77012The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not req…9.3
- CVE-2026-77013The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not res…5.3
- CVE-2026-77014A flaw was found in libsoup's SoupServer HTTP Range header p…5.3
- CVE-2026-77016The Workeera WordPress plugin before 1.0.6 does not restric…9.6
- CVE-2026-77017The Workeera WordPress plugin before 1.0.6 does not restric…7.7
Are you affected by CVE-2026-7701?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
