CVE-2026-76796

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.0
MEDIUM

Description

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).

Published
September 15, 2026 8:17 PM
Last Modified
September 15, 2026 8:17 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-73

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.