SB20260824293 - Use of Incorrectly-Resolved Name or Reference in Notepad++



SB20260824293 - Use of Incorrectly-Resolved Name or Reference in Notepad++

Published: August 24, 2026

Security Bulletin ID SB20260824293
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-77605)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to use of incorrectly-resolved name or reference in the \"Run by system\" feature when handling a user-selected .txt file that has a sibling .txt.cmd file in the same directory. A remote attacker can place a crafted sibling .txt.cmd file and trick the victim into triggering \"Run by system\" on the .txt file to execute arbitrary commands.

User interaction is required to trigger the vulnerable action.


Remediation

Install update from vendor's website.