Vulnerability in Parsec Application Allows UNC Path Exploitation
CVE-2026-25039

8.8HIGH

Key Information:

Vendor

Scille

Vendor
CVE Published:
20 July 2026

What is CVE-2026-25039?

The Parsec application, a cloud-based solution for secure file sharing, contains a vulnerability related to improper input validation of workspace names. When users create a workspace with a name that includes a '' character, the application can potentially evaluate this as a UNC path. If the specified UNC path is invalid, the application may become unresponsive. Conversely, if the path is valid, it allows interaction with the UNC path, granting the attacker the possibility to retrieve NTLM hashes, which could compromise user credentials. Proper validation and sanitization of the workspace name input are crucial to mitigating this issue.

Affected Version(s)

parsec-cloud < 3.3.3-rc.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.