Remote Code Execution Vulnerability in SConnect by Thales Group
CVE-2026-18397

9.4CRITICAL

Key Information:

Vendor

Thales

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-18397?

This vulnerability allows unauthenticated remote code execution due to weaknesses in cryptographic protocols and improper memory management within the SConnect native host component. Attackers can exploit an unrestricted messaging interface, enabling malicious input to circumvent established security measures and ultimately execute arbitrary code on the victim's machine.

Affected Version(s)

SConnect 0 < 2.16.1.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thales would like to thank James Arnott from Bay Area Labs for his coordinated disclosure and valuable contribution.
.