Sandbox-based Isolation Software Vulnerability in Sandboxie-Plus
CVE-2026-34527

2LOW

Key Information:

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-34527?

In Sandboxie-Plus versions 1.17.2 and earlier, a flaw in the SbieIniServer::HashPassword function improperly converts SHA-1 digests to hexadecimal. This vulnerability causes the high nibble of each byte to shift incorrectly, significantly reducing password hash entropy from 160 bits to 80 bits. By utilizing an unsalted SHA-1 scheme, this flaw enhances the potential for brute-force attacks on stored passwords, making it critical for users to upgrade to version 1.17.3 or later to mitigate risks.

Affected Version(s)

Sandboxie < 1.17.3

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.