CVE-2026-8993

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) El componente D.Launcher 2 del ecosistema de cliente eID eslovaco contiene una vulnerabilidad de Procesamiento Incorrecto de Gestor de URL. La aplicación registra múltiples gestores de URL personalizados que podrían ser explotados para iniciar una autenticación NTLM completa o una conexión SMB a la infraestructura del atacante y para llevar a cabo ataques SSRF (Server Side Request Forgery). Se requiere la interacción del usuario, ya que la víctima potencial necesita abrir una URL especialmente diseñada.

02 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 12:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-8993

Mitre link : CVE-2026-8993

CVE.ORG link : CVE-2026-8993


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor