PT-2026-76777 · Notepad++ · Notepad++

CVE-2026-71858

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

5.4

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.7
Description Macros loaded from an attacker-controlled shortcuts.xml file can bypass the HMAC (Hash-based Message Authentication Code) validation applied to UserDefinedCommands. This allows the invocation of Scintilla actions and the internal Open in Default Viewer command within an elevated process. Consequently, a local attacker who can influence settingsDir may achieve protected file modification and conditional elevated command execution when a user triggers the macro.
Recommendations Update to version 8.9.7.

Exploit

Fix

Protection Mechanism Failure

OS Command Injection

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71858
GHSA-F4RJ-VQQ4-WVG4

Affected Products

Notepad++