Sandbox-based Isolation Software Vulnerability in Sandboxie-Plus
CVE-2026-34527
2LOW
What is CVE-2026-34527?
In Sandboxie-Plus versions 1.17.2 and earlier, a flaw in the SbieIniServer::HashPassword function improperly converts SHA-1 digests to hexadecimal. This vulnerability causes the high nibble of each byte to shift incorrectly, significantly reducing password hash entropy from 160 bits to 80 bits. By utilizing an unsalted SHA-1 scheme, this flaw enhances the potential for brute-force attacks on stored passwords, making it critical for users to upgrade to version 1.17.3 or later to mitigate risks.
Affected Version(s)
Sandboxie < 1.17.3
