๐Ÿ” CVE Alert

CVE-2026-107611

HIGH 7.1

Out-of-bounds read in TightVNC Viewer ZRLE palette decoding

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer.

CWE CWE-125
Vendor glavsoft
Product tightvnc
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for glavsoft tightvnc

Be the first to know when new high vulnerabilities affecting glavsoft tightvnc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GlavSoft / TightVNC
0 < 2.8.88

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sourceforge.net: https://sourceforge.net/p/vnc-tight/bugs/1657/ tightvnc.com: https://www.tightvnc.com/whatsnew.php

Credits

Arjun Basnet from Securin