Description
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local File Read
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the LoadImageAsPngBase64 endpoint of Newell Brands DYMO Connect Desktop. It accepts a file path parameter without adequate validation, enabling the caller to supply a crafted path that allows the service to read any image file on the host filesystem that matches an allowed extension. This flaw permits an attacker with local access to read arbitrary image files outside the intended directory scope, potentially leading to unauthorized disclosure of the image content.

Affected Systems

Newell Brands: DYMO Connect Desktop versions prior to 1.6.2 are affected. The fix in version 1.6.2 limits access by file extension only, but does not restrict directory location, so the residual risk of reading any file with an accepted image extension remains.

Risk and Exploitability

The CVSS score of 5.1 classifies the issue as medium severity, while the EPSS < 1% indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The service; an adversary needs the ability to issue requests to the internal service, typically by being on the same machine or having compromised credentials to communicate with the application. No privileged access is required beyond the ability to call the service, but the ability to read sensitive files may depend on the file system permissions of the service process.

Generated by OpenCVE AI on September 18, 2026 at 15:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official fix by upgrading to Newell Brands DYMO Connect Desktop version 1.6.2 or later.
  • If an upgrade is not feasible, enforce restrictive file system permissions so that the service cannot access directories containing sensitive data and limit its ability to read arbitrary images with permitted extensions.
  • Restrict the internal web service to local interfaces or secure it with firewall rules, thereby preventing remote attackers from reaching the vulnerable endpoint.

Generated by OpenCVE AI on September 18, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Newell Brands
Newell Brands dymo Connect Desktop
Vendors & Products Newell Brands
Newell Brands dymo Connect Desktop

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).
Title Newell Brands DYMO Connect Desktop improper file path validation
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Newell Brands Dymo Connect Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-22T16:22:14.932Z

Reserved: 2026-08-19T18:55:45.247Z

Link: CVE-2026-76796

cve-icon Vulnrichment

Updated: 2026-09-22T16:22:12.113Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:56.977

Modified: 2026-09-22T17:17:24.467

Link: CVE-2026-76796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:30:11Z

Weaknesses
  • CWE-73

    External Control of File Name or Path