PT-2026-96853 · Notepad++ · Notepad++
CVE-2026-86056
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Notepad++ versions prior to 8.9.8
Description
The NPPM SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts
lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members without checking for null. A process running at the same or a higher Windows integrity level on the same desktop can send NPPM SAVESESSION with a null lParam, resulting in the immediate termination of the application, causing a denial of service and loss of unsaved documents.Recommendations
Update to version 8.9.8.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notepad++