In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
References
| Link | Resource |
|---|---|
| https://github.com/TigerVNC/tigervnc/commit/0b5cab169d847789efa54459a87659d3fd484393 | Patch |
| https://groups.google.com/g/tigervnc-announce/c/anHL9WLshLI | Mailing List Patch |
| https://sourceforge.net/projects/tigervnc/files/stable/1.16.2 | Release Notes |
| https://www.openwall.com/lists/oss-security/2026/03/26/7 | Mailing List Third Party Advisory |
Configurations
History
02 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tigervnc
Tigervnc tigervnc |
|
| CPE | cpe:2.3:a:tigervnc:tigervnc:*:*:*:*:*:*:*:* | |
| References | () https://github.com/TigerVNC/tigervnc/commit/0b5cab169d847789efa54459a87659d3fd484393 - Patch | |
| References | () https://groups.google.com/g/tigervnc-announce/c/anHL9WLshLI - Mailing List, Patch | |
| References | () https://sourceforge.net/projects/tigervnc/files/stable/1.16.2 - Release Notes | |
| References | () https://www.openwall.com/lists/oss-security/2026/03/26/7 - Mailing List, Third Party Advisory |
30 Mar 2026, 13:26
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Mar 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 23:16
Updated : 2026-04-02 20:16
NVD link : CVE-2026-34352
Mitre link : CVE-2026-34352
CVE.ORG link : CVE-2026-34352
JSON object : View
Products Affected
tigervnc
- tigervnc
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
