MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user.
References
| Link | Resource |
|---|---|
| https://mobaxterm.mobatek.net/download-home-edition.html | Vendor Advisory |
| https://www.vulncheck.com/advisories/mobaxterm-notepad-unquoted-service-path | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-09 16:16
Updated : 2026-06-17 10:25
NVD link : CVE-2026-25866
Mitre link : CVE-2026-25866
CVE.ORG link : CVE-2026-25866
JSON object : View
Products Affected
mobatek
- mobaxterm
CWE
CWE-428
Unquoted Search Path or Element
