CVE-2026-0776Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the discord_rpc module. The product loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-27057.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-01-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-28: 1Mentions · 2026-04-08: 1Technical Details · 2026-01-28: 1Technical Details · 2026-04-08: 101-2804-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    Node.js module resolution on Windows allows local privilege escalation when applications search C:\node_modules. Discord desktop app (CVE-2026-0776) remains unpatched - any user can plant malicious modules for code execution on app launch. #DFIR_Radar

    Post summary

    A Windows‑specific local privilege escalation flaw in Node.js module resolution allows malicious modules to execute code in the Discord app, which remains unpatched and poses a potential risk, but no PoC, tool, or active exploitation is reported.

    10010177
    1.7K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-040|CVE-2026-0776] (0Day) Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability (CVSS 7.3; Credit: T. Doğa Gelişli) https://www.zerodayinitiative.com/advisories/ZDI-26-040/

    Post summary

    Zero Day Initiative discloses CVE-2026-0776, a local privilege escalation vulnerability in Discord client with CVSS 7.3; no PoC, exploit, or patch details are provided.

    00020550
    5.3K followersView on X

Explore more