Improper URL Handler Processing Vulnerability in D.Launcher Component of Slovak eID Client
CVE-2026-8993

6.5MEDIUM

Key Information:

Vendor

Ditec A.s.

Vendor
CVE Published:
2 June 2026

What is CVE-2026-8993?

The D.Launcher component of the Slovak eID client ecosystem contains a vulnerability that arises from improper URL handler processing. This flaw allows an attacker to register multiple custom URL handlers, which can be leveraged to initiate unauthorized NTLM authentication or establish SMB connections to malicious infrastructure. Furthermore, it opens the door to server-side request forgery (SSRF) attacks. For exploitation, user interaction is necessary, as the target must open a specially crafted URL.

Affected Version(s)

D.Launcher 2 0 < 2.0.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martin Orem from Binary House
.