TLS Certificate Verification Bypass in DDE Control Panel Plugin by Deepin
CVE-2026-35207

5.4MEDIUM

Key Information:

Vendor
CVE Published:
9 April 2026

What is CVE-2026-35207?

The dde-control-center, integral to the Deepin Desktop Environment, suffers from a vulnerability in the plugin-deepinid prior to versions 6.1.80 and 5.9.9. This issue arises due to improper configuration allowing the plugin to bypass TLS certificate verification. By exploiting this flaw, a man-in-the-middle attacker can intercept user traffic destined for the deepinid cloud service, replacing user avatars with potentially malicious content. This not only misleads users but can also expose their identities through avatar retrieval, posing significant security risks.

Affected Version(s)

dde-control-center >= 6.1.35, < 6.1.80 < 6.1.35, 6.1.80

dde-control-center >= 5.5.3, < 5.9.9 < 5.5.3, 5.9.9

deepin-deepinid-plugin >= 2.0.1, <= 2.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.