Dynamic Library Update Issue in SzafirHost Software from Elektroniczny Podpis
CVE-2026-26928

8.7HIGH

Key Information:

Vendor
CVE Published:
2 April 2026

What is CVE-2026-26928?

The SzafirHost software has a vulnerability that allows an attacker to upload malicious files due to inadequate verification of dynamic library files. While legitimate JAR files are verified for integrity using trusted hashes and digital signatures, the application fails to verify similar checks for uploaded DLL, SO, JNILIB, or DYLIB files. This oversight could enable attackers to execute harmful code stored in the users' /temp directory when the application attempts to run the compromised libraries.

Affected Version(s)

SzafirHost 0 < 1.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Leszczyński
.