What is CVE-2026-52886?
CVE-2026-52886 is a path traversal vulnerability in Notepad++ versions prior to 8.9.7, caused by insufficient normalization of the backupFilePath attribute in session.xml. This could allow an attacker to write arbitrary files using parent-directory sequences during snapshot-mode restoration. Users are advised to update Notepad++ to version 8.9.7 or later.
Azərbaycanca: CVE-2026-52886 Notepad++-un 8.9.7-dən əvvəlki versiyalarında "session.xml" faylındakı backupFilePath atributunun düzgün normallaşdırılmaması səbəbindən yaranan zəiflikdir. Bu, snapshot-mode bərpası zamanı təcavüzkarın valideyn-qovluq (path traversal) texnikaları ilə ixtiyari fayl yazmasına şərait yarada bilər. İstifadəçilərə Notepad++ proqramını ən azı 8.9.7 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Notepad++ are affected by CVE-2026-52886?
Notepad++ versions prior to 8.9.7 are affected by this vulnerability.
How can CVE-2026-52886 be exploited?
An attacker can write arbitrary files by using parent-directory (path traversal) sequences in the backupFilePath attribute of session.xml during snapshot-mode restoration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.