Sunshine
LizardByte · 11 CVEs
Sunshine: Authentication bypass via improper client certificate validation
May 22, 2026
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
Sep 23, 2025
A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
Sep 9, 2025
LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability
Sep 9, 2025
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
Jul 1, 2025
Sunshine clickjacking in the UI leads to unauthorized actions being performed
Jul 1, 2025
Sunshine improperly enforces pairing protocol request order
Jan 20, 2025
Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client
Sep 10, 2024
Sunshine's unquoted executable path could lead to hijacked execution flow
May 16, 2024
Clients removed during unpairing process may regain access if Sunshine was not restarted
Apr 8, 2024
Sunshine vulnerable to remote unauthenticated arbitrary file read
Apr 5, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-32253 | Sunshine: Authentication bypass via improper client certificate validation | CRITICAL | 0.43% | May 22, 2026 |
| CVE-2025-54081 | SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution | HIGH | 0.23% | Sep 23, 2025 |
| CVE-2025-10199 | A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows | HIGH | 0.19% | Sep 9, 2025 |
| CVE-2025-10198 | LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability | HIGH | 0.22% | Sep 9, 2025 |
| CVE-2025-53095 | Sunshine application-wide CSRF in the UI leads to command injection as Administrator | CRITICAL | 0.24% | Jul 1, 2025 |
| CVE-2025-53096 | Sunshine clickjacking in the UI leads to unauthorized actions being performed | MEDIUM | 0.24% | Jul 1, 2025 |
| CVE-2024-51738 | Sunshine improperly enforces pairing protocol request order | HIGH | 0.58% | Jan 20, 2025 |
| CVE-2024-45407 | Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client | MEDIUM | 0.34% | Sep 10, 2024 |
| CVE-2024-31226 | Sunshine's unquoted executable path could lead to hijacked execution flow | MEDIUM | 0.22% | May 16, 2024 |
| CVE-2024-31221 | Clients removed during unpairing process may regain access if Sunshine was not restarted | MEDIUM | 0.51% | Apr 8, 2024 |
| CVE-2024-31220 | Sunshine vulnerable to remote unauthenticated arbitrary file read | HIGH | 0.49% | Apr 5, 2024 |
Showing 1 to 11 of 11 CVEs