CVE-2026-8993
Estado: AplazadaMedia (6.5)—
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-74, CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-8993",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-8993",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-02T11:54:50.637774Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "incident@nbu.gov.sk",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "incident@nbu.gov.sk",
"affectedData": [
{
"vendor": "Ditec a.s.",
"product": "D.Launcher 2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.0.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-02T12:16:18.647",
"references": [
{
"url": "https://ditec.sk/static/kep/apps/release-notes/en",
"source": "incident@nbu.gov.sk"
},
{
"url": "https://www.slovensko.sk/sk/oznamy/detail/_zranitelnost-aplikacie-d-launc",
"source": "incident@nbu.gov.sk"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "incident@nbu.gov.sk",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL."
},
{
"lang": "es",
"value": "El componente D.Launcher 2 del ecosistema de cliente eID eslovaco contiene una vulnerabilidad de Procesamiento Incorrecto de Gestor de URL. La aplicación registra múltiples gestores de URL personalizados que podrían ser explotados para iniciar una autenticación NTLM completa o una conexión SMB a la infraestructura del atacante y para llevar a cabo ataques SSRF (Server Side Request Forgery). Se requiere la interacción del usuario, ya que la víctima potencial necesita abrir una URL especialmente diseñada."
}
],
"lastModified": "2026-07-22T19:10:00.120",
"sourceIdentifier": "incident@nbu.gov.sk"
}