MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s secure paths, enabling an attacker with local access to place a specially crafted DLL to be executed automatically when the victim launches the application.

Project Subscriptions

Vendors Products
Mobatek Subscribe
Mobaxterm Personal Edition Portable Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by the Mobatek team in version 26.4.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s secure paths, enabling an attacker with local access to place a specially crafted DLL to be executed automatically when the victim launches the application.
Title Arbitrary code execution in MobaXterm Personal Edition (Portable)
First Time appeared Mobatek
Mobatek mobaxterm Personal Edition Portable
Weaknesses CWE-427
CPEs cpe:2.3:a:mobatek:mobaxterm_personal_edition_portable_:26.3:*:*:*:*:*:*:*
cpe:2.3:a:mobatek:mobaxterm_personal_edition_portable_:26.4:*:*:*:*:*:*:*
Vendors & Products Mobatek
Mobatek mobaxterm Personal Edition Portable
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-06-12T14:00:36.218Z

Reserved: 2026-06-10T13:20:14.951Z

Link: CVE-2026-11879

cve-icon Vulnrichment

Updated: 2026-06-12T14:00:33.063Z

cve-icon NVD

Status : Received

Published: 2026-06-12T14:16:29.890

Modified: 2026-06-12T14:16:29.890

Link: CVE-2026-11879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T15:00:09Z

Weaknesses