Beveiligingsadvies

CVE-2026-76796

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 20:04:42
Laatst bijgewerkt 2026-09-15 20:04:42
Toegewezen door cisa-cg
CVSS-score 5.1
Status PUBLISHED

Beschrijving

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).