Generation of Predictable Numbers or Identifiers in keepassxc - #VU151868

 

Generation of Predictable Numbers or Identifiers in keepassxc - #VU151868

Published: September 23, 2026


Vulnerability identifier: #VU151868
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-340
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose SSH agent keys.

The vulnerability exists due to the use of a predictable shared memory name in Pageant SSH agent key sharing when communicating with the Pageant SSH agent on Windows. A local user can pre-create a shared memory handle with the same name to disclose SSH agent keys.

Exploitation requires the attacker to run under the same user account.


Affected software

keepassxc

Remediation

Install security update from vendor's website.

keepassxc - update to 2.8.0

External References

Related Security Bulletins