Remote Code Execution Vulnerability in BareBones BBEdit Java Language Module
CVE-2026-82604

5.3MEDIUM

Key Information:

Vendor

Barebones

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82604?

A vulnerability exists in BareBones BBEdit affecting versions up to 15.5.5, where an issue within the Java Language Module can lead to uncontrolled recursion. This flaw enables potential remote exploitation, which could result in a denial-of-service attack or other malicious impacts. Users are strongly advised to upgrade to version 16.0 or later to mitigate these risks effectively.

Affected Version(s)

BBEdit 15.5.0

BBEdit 15.5.1

BBEdit 15.5.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ciphersecuritylabs (VulDB User)
.