CVE-2026-6421

7.0

Mobatek · MobaXterm Home Edition

A vulnerability in Mobatek MobaXterm Home Edition versions 26.0 and 26.1 allows for local privilege escalation via an uncontrolled search path in the msimg32.dll library.

Executive summary

A vulnerability in Mobatek MobaXterm Home Edition versions 26.0 and 26.1 permits local attackers to exploit an uncontrolled search path, potentially leading to full system compromise.

Vulnerability

The software suffers from an uncontrolled search path vulnerability (CWE-427) within the msimg32.dll library. An authenticated local user can manipulate the search path to execute arbitrary code, though the attack requires high complexity and local access.

Business impact

The vulnerability carries a CVSS score of 7.0, classifying it as a High severity issue. Successful exploitation allows a local attacker to gain elevated privileges on the host system, potentially leading to unauthorized data access, system-wide configuration changes, and complete compromise of the local machine. While local access is required, the potential for lateral movement or persistence within the environment poses a significant risk to organizational security.

Remediation

Immediate Action: Update MobaXterm Home Edition to version 26.2 or later immediately to resolve the vulnerable library path.

Proactive Monitoring: Monitor system logs for unauthorized access attempts or suspicious file system activity involving library loads within the MobaXterm installation directory.

Compensating Controls: Ensure that local users are restricted from writing to application installation directories and implement robust endpoint protection to detect unauthorized binary execution.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the provided technical reference.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for full system compromise, the urgency for remediation is high. Organizations utilizing MobaXterm Home Edition should prioritize upgrading all instances to version 26.2 to eliminate the uncontrolled search path vulnerability and mitigate the risk of local privilege escalation.

More Mobatek CVEs

Sources

Originally found and disclosed by haehanse (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.