Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal Open in Default Viewer command in an elevated Notepad++ process, allowing protected file modification and conditional elevated command execution when a local attacker influences settingsDir and a user triggers the macro. This issue is fixed in version 8.9.7. | |
| Title | Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution | |
| Weaknesses | CWE-345 CWE-693 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T20:26:38.601Z
Reserved: 2026-08-07T18:26:53.523Z
Link: CVE-2026-71858
Updated: 2026-08-17T20:26:30.359Z
Status : Received
Published: 2026-08-17T20:16:46.207
Modified: 2026-08-17T21:16:48.420
Link: CVE-2026-71858
No data.
OpenCVE Enrichment
No data.