CVE-2024-26362: Code Injection

Published Apr 10, 2024
·
Updated

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

Affected Software

4 affected components
Enpass Password Manager Desktop Client
All of the following
Enpass Password Manager=6.9.2
Any of the following
Linux Linux kernel
Microsoft Windows

Event History

Apr 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-26362?

CVE-2024-26362 is rated as a high severity vulnerability due to its potential to allow attackers to run arbitrary HTML code.

2

How does CVE-2024-26362 impact Enpass Password Manager?

CVE-2024-26362 allows attackers to exploit the HTML injection vulnerability to create crafted notes that can execute malicious HTML code.

3

Which versions of Enpass Password Manager are affected by CVE-2024-26362?

CVE-2024-26362 affects Enpass Password Manager Desktop Client version 6.9.2.

4

How do I fix CVE-2024-26362?

To fix CVE-2024-26362, update the Enpass Password Manager Desktop Client to the latest version that has addressed this vulnerability.

5

Can CVE-2024-26362 affect both Windows and Linux users?

Yes, CVE-2024-26362 affects the Enpass Password Manager Desktop Client on both Windows and Linux platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203