What is CVE-2026-14478?
CVE-2026-14478 allows a local low-privileged attacker to exploit a maliciously crafted executable to interfere with `named pipes` on the victim's machine. This enables the injection of unauthenticated IPC messages and modification of pipe permissions or ownership, potentially compromising confidentiality, integrity, and availability. Users should avoid executing files from untrusted sources.
Azərbaycanca: CVE-2026-14478, təcavüzkarın xüsusi hazırlanmış icra olunan fayl vasitəsilə qurbanın maşınında aşağı səlahiyyətlərlə belə `named pipe` mexanizminə müdaxilə edərək autentifikasiyasız IPC mesajları göndərməsinə, boru icazələrini dəyişməsinə və ya sahibliyini ələ keçirməsinə imkan verir. Bu zəiflik məxfilik, bütövlük və əlçatanlığa ciddi təsir göstərə bilər. İstifadəçilərə etibarsız mənbələrdən gələn faylları icra etməmələri tövsiyə olunur.
FAQ2
What privilege level does an attacker need to exploit CVE-2026-14478?
The attacker needs local low-privileged access.
Through which mechanism is this vulnerability exploited?
It is exploited via a maliciously crafted executable that interferes with `named pipes`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.