Improper Input Validation in DYMO Connect Desktop by Newell Brands
CVE-2026-76796
5.1MEDIUM
What is CVE-2026-76796?
The LoadImageAsPngBase64 endpoint in the DYMO Connect Desktop application allows an attacker to exploit a lack of sufficient validation on the file path parameter. This design flaw enables unauthorized access to arbitrary image files on the host filesystem, potentially exposing sensitive data. Although access is restricted by file extensions, the limitation does not prevent the risks associated with reading files from unintended directories, making it critical for users to adopt best security practices. The issue was addressed in version 1.6.2, yet users should remain vigilant about the acceptable residual risks.
Affected Version(s)
DYMO Connect Desktop 0
DYMO Connect Desktop 0 < 1.6.2
DYMO Connect Desktop 1.6.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
René de Sain, Rechtspraak (Netherlands Judiciary)
