VORANT. Threat Intelligence Sign in Get the full feed

Szafir SDK flaws enable arbitrary code execution

medium vulnerability

Two vulnerabilities in Poland's Szafir SDK Web plugin let attackers spoof origin URLs and load unsigned malicious libraries for code execution.

CERT Polska coordinated disclosure of two vulnerabilities in Szafir SDK Web, a browser plug-in used to launch the SzafirHost application for downloading required files. CVE-2026-26927 allows an unauthenticated attacker to craft a malicious website that invokes SzafirHost with an arbitrary document_base_url parameter, which is not validated against the actual calling application. If a victim has previously accepted execution with the "remember" option, the application will silently launch in the attacker-controlled context without any further prompt, potentially fetching additional files from the attacker's site.

CVE-2026-26928 affects SzafirHost's dynamic library update mechanism. While JAR files are checked against a trusted hash list or vendor signature, the application fails to verify hashes or digital signatures for DLL, SO, JNILIB, or DYLIB files, allowing an attacker to supply a malicious native library that is saved to the user's temp folder and executed. Both issues were reported through CERT Polska's coordinated vulnerability disclosure process and have been patched in versions 0.0.17.4 and 1.1.0 respectively. No evidence of active exploitation is mentioned in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-26927CVE-2026-26928

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-26927

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free