Remote Code Execution in Algernon Web Server for Windows
CVE-2026-52792

8.7HIGH

Key Information:

Vendor

Xyproto

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-52792?

Algernon, a self-contained pure-Go web server, prior to version 1.17.9 on Windows, has a vulnerability where it fails to properly handle file extensions that may contain NTFS-specific suffixes. An attacker can exploit this by crafting requests that append these suffixes to certain script files, leading the server to expose raw script code. This exposure can reveal sensitive data such as database credentials and API keys. The issue arises because the server does not properly validate the requested files, allowing for unauthorized access to sensitive information. The vulnerability is not present on Linux or macOS systems and has been resolved in the latest version.

Affected Version(s)

algernon < 1.17.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.