Dynamic Library Update Issue in SzafirHost Software from Elektroniczny Podpis
CVE-2026-26928
8.7HIGH
What is CVE-2026-26928?
The SzafirHost software has a vulnerability that allows an attacker to upload malicious files due to inadequate verification of dynamic library files. While legitimate JAR files are verified for integrity using trusted hashes and digital signatures, the application fails to verify similar checks for uploaded DLL, SO, JNILIB, or DYLIB files. This oversight could enable attackers to execute harmful code stored in the users' /temp directory when the application attempts to run the compromised libraries.
Affected Version(s)
SzafirHost 0 < 1.1.0
