๐Ÿ” CVE Alert

CVE-2026-68766

HIGH 7.8

hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.

CWE CWE-88
Vendor hashcat
Product hashcat
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for hashcat hashcat

Be the first to know when new high vulnerabilities affecting hashcat hashcat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

hashcat / hashcat
0 โ‰ค 7.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hashcat/hashcat/issues/4738 github.com: https://github.com/hashcat/hashcat github.com: https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4 github.com: https://github.com/hashcat/hashcat/blob/v7.1.2/src/restore.c#L365-L369 vulncheck.com: https://www.vulncheck.com/advisories/hashcat-through-arbitrary-file-write-via-restore-file-option-injection

Credits

Piotr Kowalczyk