SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
Published Oct 1, 2026
9.4
CRITICALCVSS 4.0
Description
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Affected products
-
- Version 0StatusaffectedConstraints<2.16.1.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://www.thalesgroup.com/en/product-security-incident-response | vendor-advisory |
Change history (0)
No recorded changes yet.