CVE-2026-79079

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

  • Published Sep 21, 2026
  • CVSS 7.8 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2026-79079 at the National Vulnerability Database