CVE-2026-18397
SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
| CWE | CWE-347 CWE-130 CWE-457 CWE-252 |
| Vendor | thales |
| Product | sconnect |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for thales sconnect
Be the first to know when new unknown vulnerabilities affecting thales sconnect are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Thales / SConnect
0 < 2.16.1.0
References
Credits
Thales would like to thank James Arnott from Bay Area Labs for his coordinated disclosure and valuable contribution.