CVE-2026-52754

National Security Agency (NSA) · Ghidra

Ghidra versions prior to 12 are affected by a security vulnerability requiring immediate attention.

Executive summary

Ghidra versions before 12 contain a high-severity vulnerability that requires an immediate update to ensure system integrity.

Vulnerability

This vulnerability affects Ghidra versions prior to 12, potentially enabling attackers to perform unauthorized actions within the application. The flaw represents a significant risk to the security of the analysis environment and requires a timely upgrade.

Business impact

With a CVSS score of 8.8, this vulnerability is considered high-severity. A successful exploit could lead to unauthorized access or manipulation of the data being analyzed, which is particularly concerning for organizations using Ghidra to handle proprietary or sensitive binaries.

Remediation

Immediate Action: Update the Ghidra installation to version 12 or the most recent available version to remediate the underlying security flaw.

Proactive Monitoring: Monitor for any anomalous activity or unauthorized file access attempts within the directories where Ghidra projects are stored.

Compensating Controls: Apply principle-of-least-privilege access controls to the user accounts running Ghidra to limit the potential reach of an exploit.

Exploitation status

Public Exploit Available: False

Analyst recommendation

It is strongly recommended that all users of Ghidra update to version 12 or higher immediately. Addressing this vulnerability is critical to protecting the confidentiality and integrity of your reverse engineering projects and the underlying host systems.