Incorrect Permission Assignment in TightVNC Server for Windows
CVE-2026-107612

7.8HIGH

Key Information:

Vendor

Glavsoft

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107612?

A vulnerability in TightVNC Server for Windows allows local authenticated users to exploit incorrect permission assignments, enabling them to read or overwrite inter-process communication handles. This occurred due to a named shared memory segment being created with a NULL DACL, making it accessible for low-privileged processes. The segment name is predictable based on time, allowing malicious users to tamper with IPC channels of a service running with elevated privileges. This can lead to potential privilege escalation, disclosure of sensitive session data, or even denial of service.

Affected Version(s)

TightVNC Windows 0 < 2.8.88

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.