Generation of Predictable Numbers or Identifiers in keepassxc - #VU151868
Published: September 23, 2026
Vulnerability details
The vulnerability allows a local user to disclose SSH agent keys.
The vulnerability exists due to the use of a predictable shared memory name in Pageant SSH agent key sharing when communicating with the Pageant SSH agent on Windows. A local user can pre-create a shared memory handle with the same name to disclose SSH agent keys.
Exploitation requires the attacker to run under the same user account.