CVE-2026-25866
MobaXterm < 26.1 Notepad++ Unquoted Service Path
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user.
| CWE | CWE-428 |
| Vendor | mobatek |
| Product | mobaxterm |
| Published | Mar 9, 2026 |
| Last Updated | Mar 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for mobatek mobaxterm
Be the first to know when new high vulnerabilities affecting mobatek mobaxterm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Mobatek / MobaXterm
0 < 26.1
References
Credits
Spektion Research Team VulnCheck