CVE-2026-20518

In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.

  • Published Sep 7, 2026
  • CVSS 4.4 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-20518 at the National Vulnerability Database