CVE-2026-52754
National Security Agency (NSA) · Ghidra
Ghidra versions prior to 12 are affected by a security vulnerability requiring immediate attention.
Executive summary
Ghidra versions before 12 contain a high-severity vulnerability that requires an immediate update to ensure system integrity.
Vulnerability
This vulnerability affects Ghidra versions prior to 12, potentially enabling attackers to perform unauthorized actions within the application. The flaw represents a significant risk to the security of the analysis environment and requires a timely upgrade.
Business impact
With a CVSS score of 8.8, this vulnerability is considered high-severity. A successful exploit could lead to unauthorized access or manipulation of the data being analyzed, which is particularly concerning for organizations using Ghidra to handle proprietary or sensitive binaries.
Remediation
Immediate Action: Update the Ghidra installation to version 12 or the most recent available version to remediate the underlying security flaw.
Proactive Monitoring: Monitor for any anomalous activity or unauthorized file access attempts within the directories where Ghidra projects are stored.
Compensating Controls: Apply principle-of-least-privilege access controls to the user accounts running Ghidra to limit the potential reach of an exploit.
Exploitation status
Public Exploit Available: False
Analyst recommendation
It is strongly recommended that all users of Ghidra update to version 12 or higher immediately. Addressing this vulnerability is critical to protecting the confidentiality and integrity of your reverse engineering projects and the underlying host systems.