Arbitrary Code Execution in MobaXterm Personal Edition by Mobatek
CVE-2026-11967

8.5HIGH

Key Information:

Vendor

Mobatek

Vendor
CVE Published:
12 June 2026

What is CVE-2026-11967?

The MobaXterm Personal Edition (Portable), specifically in version 26.3 (Build 5154), is susceptible to a vulnerability that allows for arbitrary code execution. This occurs when the application loads a malicious DLL file placed in the same directory as its executable. During the startup process, MobaXterm automatically loads the winspool.drv library from this location, enabling an attacker with local access to execute crafted DLLs alongside the application. Users should be aware of this risk and take appropriate measures to secure their installations.

Affected Version(s)

MobaXterm Personal Edition (Portable) 26.3

MobaXterm Personal Edition (Portable) 26.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro J. Nunez-Cacho Fuentes (@tunelko)
.