CVE-2026-23863
Estado: AnalizadaMedia (6.5)—
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-158
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23863",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-23863",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-01T17:40:45.569668Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-assign@fb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve-assign@fb.com",
"affectedData": [
{
"vendor": "Facebook",
"product": "WhatsApp Desktop for Windows",
"versions": [
{
"status": "affected",
"version": "2.3000.*.252500",
"lessThan": "2.3000.1032164386.258709",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-01T16:16:29.843",
"references": [
{
"url": "https://www.facebook.com/security/advisories/cve-2026-23863",
"tags": [
"Third Party Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://www.whatsapp.com/security/advisories/2026",
"tags": [
"Vendor Advisory"
],
"source": "cve-assign@fb.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-158"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild."
}
],
"lastModified": "2026-06-17T10:22:13.297",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "1E1C0BD0-0D92-438F-AB63-A267635A5FDF",
"versionEndExcluding": "2.3000.1032164386.258709"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-assign@fb.com"
}