Improper Input Validation in DYMO Connect Desktop by Newell Brands
CVE-2026-76796

5.1MEDIUM

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-76796?

The LoadImageAsPngBase64 endpoint in the DYMO Connect Desktop application allows an attacker to exploit a lack of sufficient validation on the file path parameter. This design flaw enables unauthorized access to arbitrary image files on the host filesystem, potentially exposing sensitive data. Although access is restricted by file extensions, the limitation does not prevent the risks associated with reading files from unintended directories, making it critical for users to adopt best security practices. The issue was addressed in version 1.6.2, yet users should remain vigilant about the acceptable residual risks.

Affected Version(s)

DYMO Connect Desktop 0

DYMO Connect Desktop 0 < 1.6.2

DYMO Connect Desktop 1.6.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

René de Sain, Rechtspraak (Netherlands Judiciary)
.