CVE-2026-18397 CRITICAL

CVE-2026-18397: SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

Vendor Thales
Product SConnect
Weakness CWE-347
Published October 1, 2026
Last update October 1, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

Key dates

02Disclosure timeline

October 1, 2026 CVE published

Related vulnerabilities

04Related CVE