CVE-2026-30332

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.
Configurations

No configuration.

History

02 Apr 2026, 18:16

Type Values Removed Values Added
CWE CWE-367

02 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 16:16

Updated : 2026-04-03 16:10


NVD link : CVE-2026-30332

Mitre link : CVE-2026-30332

CVE.ORG link : CVE-2026-30332


JSON object : View

Products Affected

No product.

CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition