PT-2026-98316 · Unknown · Root Browser Classic

·

CVE-2026-85082

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Root Browser Classic version 3.3.0
Description Root Browser Classic passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command. This lack of separation can allow for command injection, where an attacker could execute arbitrary commands on the system by manipulating the database path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85082

Affected Products

Root Browser Classic