CVE-2026-18397 PUBLISHED

SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

Assigner: THA-PSIRT
Reserved: 30.07.2026 Published: 01.10.2026 Updated: 01.10.2026

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.

The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Thales
Product SConnect
Versions Default: unaffected
  • affected from 0 to 2.16.1.0 (excl.)

Credits

  • Thales would like to thank James Arnott from Bay Area Labs for his coordinated disclosure and valuable contribution. finder

References

Problem Types

  • CWE-347 Improper verification of cryptographic signature CWE
  • CWE-130 Improper handling of length parameter inconsistency CWE
  • CWE-457 Use of uninitialized variable CWE
  • CWE-252 Unchecked return value CWE

Impacts

  • CAPEC-475 Signature Spoofing by Improper Validation
  • CAPEC-47 Buffer Overflow via Parameter Expansion
  • CAPEC-463 Padding Oracle Crypto Attack