Description
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.

The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Published: 2026-10-01
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Unauthenticated remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the SConnect native host component, where a combination of cryptographic weaknesses and memory management flaws can be abused to execute arbitrary code without authentication. This flaw allows an attacker to forge malicious input that bypasses security checks, leading to remote code execution on the victim machine. The weakness falls under several common weakness enumerations including lack of input validation (CWE‑130), improper authorization (CWE‑252), uninitialized memory usage (CWE‑347), and improper resource handling (CWE‑457). Consequently, an attacker who can reach the vulnerable messaging interface can run arbitrary code with the privileges of the native host process, potentially compromising the entire system.

Affected Systems

The affected software is Thales SConnect, a connectivity platform that facilitates secure messaging between web applications and native host components. Specific product versions are not listed in the advisory, but any installation of the SConnect native host component may be vulnerable.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity, and the lack of an available EPSS score prevents a precise exploitation probability estimate, but the absence of a known KEV listing does not diminish the risk. Based on the description, the likely attack vector is through an unrestricted messaging interface exposed to web content, allowing an attacker to craft messages from a malicious web page that interacts with the native host. Exploitation would require the victim to load or trust the attacker‑controlled page, and no prior authentication is needed. The exploit is therefore potentially exploitable from any external source that can trigger the messaging interface.

Generated by OpenCVE AI on October 1, 2026 at 23:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply the latest SConnect update that contains the fix for the remote code execution vulnerability.
  • Configure the native host to disable or harden the unrestricted messaging interface, ensuring only authenticated or trusted origin URLs can transmit data.
  • Implement strict input validation and boundary checks on all messages received by the native host to prevent malformed or malicious payloads from causing memory corruption or execution of unintended code.

Generated by OpenCVE AI on October 1, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Title SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
Weaknesses CWE-130
CWE-252
CWE-347
CWE-457
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: THA-PSIRT

Published:

Updated: 2026-10-01T21:49:42.379Z

Reserved: 2026-07-30T14:55:56.425Z

Link: CVE-2026-18397

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:01.220

Modified: 2026-10-01T22:17:01.220

Link: CVE-2026-18397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:30:14Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-252

    Unchecked Return Value

  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-457

    Use of Uninitialized Variable