TLS Certificate Verification Bypass in DDE Control Panel Plugin by Deepin
CVE-2026-35207
5.4MEDIUM
What is CVE-2026-35207?
The dde-control-center, integral to the Deepin Desktop Environment, suffers from a vulnerability in the plugin-deepinid prior to versions 6.1.80 and 5.9.9. This issue arises due to improper configuration allowing the plugin to bypass TLS certificate verification. By exploiting this flaw, a man-in-the-middle attacker can intercept user traffic destined for the deepinid cloud service, replacing user avatars with potentially malicious content. This not only misleads users but can also expose their identities through avatar retrieval, posing significant security risks.
Affected Version(s)
dde-control-center >= 6.1.35, < 6.1.80 < 6.1.35, 6.1.80
dde-control-center >= 5.5.3, < 5.9.9 < 5.5.3, 5.9.9
deepin-deepinid-plugin >= 2.0.1, <= 2.0.9
