PT-2026-66620 · Rapidraw · Rapidraw

CVE-2026-64816

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RapidRAW versions prior to 1.6.0
Description Insufficient validation of the lutPath field in preset files before it is processed by the File::open() function in lut processing.rs allows for a credential leak on Windows systems. An attacker can use a UNC (Universal Naming Convention) path—a standard for specifying the location of shared resources on a network—within the lutPath variable to trigger an outbound SMB connection to a remote host, resulting in the exposure of the victim's NTLMv2 credentials. This issue can be triggered when the application automatically fetches community presets from a remote repository via the Community tab or when a user imports a preset file through the handle import presets from file function in file management.rs.
Recommendations Update RapidRAW to version 1.6.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64816

Affected Products

Rapidraw