Arbitrary Code Execution Vulnerability in MobaXterm Personal Edition
CVE-2026-11879
8.5HIGH
What is CVE-2026-11879?
MobaXterm Personal Edition (Portable) version 26.3 (Build 5154) contains a vulnerability that allows local attackers to execute arbitrary code. The application attempts to load specific DLLs from a user-modifiable temporary directory before checking system secure paths. This design flaw permits an attacker with local access to place maliciously crafted DLL files in that directory, leading the application to execute them upon startup. Users are advised to be cautious and consider updating to the latest version to mitigate potential risks.
Affected Version(s)
MobaXterm Personal Edition (Portable) 26.3
MobaXterm Personal Edition (Portable) 26.4
