PT-2026-58886 · Notepad++ · Notepad++

CVE-2026-52886

·

Published

2026-07-15

·

Updated

2026-09-12

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.7
Description Notepad++ fails to perform path normalization when validating the backupFilePath attribute from session.xml using the std::wstring::starts with function. This allows the use of parent-directory sequences during snapshot-mode restoration to read arbitrary user-readable files located outside the intended backup directory into an editor tab.
Recommendations Update to version 8.9.7.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52886
GHSA-RQFM-PW34-R7J6

Affected Products

Notepad++