CVE-2026-25866
7.8Mobatek · MobaXterm
MobaXterm versions prior to 26.1 are vulnerable to an uncontrolled search path element issue, allowing local attackers to execute arbitrary code by placing a malicious file in the search path.
Executive summary
A critical uncontrolled search path element vulnerability in MobaXterm allows a local attacker to achieve arbitrary code execution.
Vulnerability
This vulnerability involves an uncontrolled search path element where the application invokes Notepad++ via WinExec using an unqualified path. A local user with low privileges can exploit this behavior by placing a malicious executable in a directory that precedes the intended path in the search order.
Business impact
The ability for a local attacker to achieve arbitrary code execution poses a severe risk to system integrity and confidentiality. Given the CVSS score of 7.8, this flaw represents a High severity risk, as it could allow unauthorized control over the user session and potentially facilitate privilege escalation or persistent access within the local environment.
Remediation
Immediate Action: Update MobaXterm to version 26.1 or later immediately to resolve the path search vulnerability.
Proactive Monitoring: Monitor local system logs for unexpected process executions originating from the MobaXterm working directory or common search path locations.
Compensating Controls: Restrict write access to directory paths included in the system PATH environment variable to prevent unauthorized users from planting malicious binaries.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant security risk for environments where MobaXterm is deployed, as it allows local code execution. System administrators should prioritize updating all instances of MobaXterm to version 26.1 or later across the organization. Failure to patch allows local users to potentially escalate their privileges or compromise the security of the host system.
More Mobatek CVEs
Sources
Originally found and disclosed by Spektion Research Team, with VulnCheck (coordinator), per the CVE Program record.