Ollama Windows updater flaws enable silent RCE
Two chained flaws in Ollama for Windows let attackers bypass update signature checks and path-traverse malicious payloads into the Startup folder for silent, automatic code execution.
CERT Polska coordinated disclosure of two vulnerabilities affecting Ollama for Windows' auto-update mechanism. CVE-2026-42248 shows that, unlike other platforms, the Windows update verification routine unconditionally returns success, meaning no digital signature or trust validation is performed before staging or executing update payloads. CVE-2026-42249 is a path traversal RCE where attacker-controlled HTTP response headers are used to construct local file paths via filepath.Join without sanitization, allowing writes outside the intended staging directory—including into the Windows Startup folder.
When chained, an attacker capable of influencing update responses (e.g., via a man-in-the-middle or compromised update channel) can deliver a malicious executable that is written to a persistence location and silently executed without any user interaction, since Ollama for Windows performs automatic updates by default. This results in automatic, persistent code execution without user awareness.
Versions 0.12.10 through 0.17.5 were confirmed vulnerable during testing; other versions were untested but may also be affected. The maintainers were notified early but did not respond with vulnerability details or a confirmed affected version range, leaving the full scope of impact unclear. No patch status or exploitation-in-the-wild evidence is mentioned in the report.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-42248
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free