MIME Handler Vulnerability in Wine Affects Windows Executable File Types
CVE-2026-48831

7.3HIGH

Key Information:

Vendor

Winehq

Status
Vendor
CVE Published:
24 May 2026

What is CVE-2026-48831?

Wine contains a vulnerability related to its .desktop file, which registers as a MIME handler for various Windows executable file types, including EXE files. Under certain configurations, this vulnerability results in EXE files being executed without proper safeguards, using the permissions of the user who invoked it. This situation poses security risks by potentially allowing malicious files to escape from Flatpak and Snap sandboxes. While there are concerns regarding the usability impacts of any fix, this vulnerability calls for increased attention to handling executable files securely within Wine environments.

Affected Version(s)

Wine 0.9 <= 11.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.