Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76796— Newell Brands DYMO Connect Desktop improper file path validation

Quick assessment

Affected
Newell Brands DYMO Connect Desktop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Newell Brands DYMO Connect Desktop 本地 Web 服务中的 端点在处理文件路径参数时缺乏充分验证,导致攻击者可通过构造特定路径,读取主机文件系统上超出预期范围之外的任意图像文件。该问题已在 1.6.2 版本中修复。 修复方式是通过限制允许的文件扩展名来控制访问范围,但并未对目录进行限制。因此,只要文件具有允许的图像扩展名,仍可在任意位置被读取(此为设计上的残留风险,已被接受)。

CVSS 4.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76796

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Newell Brands DYMO Connect Desktop improper file path validation
Source: CVE Program / CVE List V5
Vulnerability Description
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Newell Brands DYMO Connect Desktop 0 ~ 1.6.2 -

II. Public POCs for CVE-2026-76796

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76796

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76796 (1)

Vendor Pages for CVE-2026-76796 (1)

Other References for CVE-2026-76796 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76796

No comments yet


Leave a comment