๐Ÿ” CVE Alert

CVE-2026-18397

UNKNOWN 0.0

SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

CWE CWE-347 CWE-130 CWE-457 CWE-252
Vendor thales
Product sconnect
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for thales sconnect

Be the first to know when new unknown vulnerabilities affecting thales sconnect are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Thales / SConnect
0 < 2.16.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
thalesgroup.com: https://www.thalesgroup.com/en/product-security-incident-response

Credits

Thales would like to thank James Arnott from Bay Area Labs for his coordinated disclosure and valuable contribution.