RDP Vulnerability in Electerm SSH Client
CVE-2026-73227

8.1HIGH

Key Information:

Vendor

Electerm

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73227?

The Electerm client, which serves as an open-source application for terminal and remote desktop connections, is susceptible to an improper input validation vulnerability. This flaw allows a malicious RDP server to manipulate the clipboard download path, effectively permitting the server to write arbitrary content outside of the intended directory. The vulnerability arises from the lack of input sanitization while handling filenames in the clipboard transfer functionality. Users are encouraged to update to version 3.15.120 or later to mitigate this risk.

Affected Version(s)

electerm < 3.15.120

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.