CVE-2026-28211General

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A maliciously crafted log file can lead to arbitrary code execution when a user reads it with log reader commands. The log reading command process speech log entries in an unsafe manner. Python expressions embedded in the log may be evaluated when when speech entries are read with log reading commands. An attacker can exploit this by convincing a user to open a malicious crafted log file and to analyze it using the log reading commands. When the log is read, attacker-controlled code may execute with the privileges of the current user. This issue does not require elevated privileges and relies solely on user interaction (opening the log file). Version 9.0 contains a fix for the issue. As a workaround, avoid using log reading commands, or at least, commands to move to next/previous log message (any message or commands for each type of message). For more security, one may disable their gestures in the input gesture dialog.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2703-03
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1General1
2026-03-031
General1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28211 (CVSS:7.8, HIGH) is Awaiting Analysis. The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability ..https://nvd.nist.gov/vuln/detail/CVE-2026-28211 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post merely references CVE-2026-28211 with its CVSS score, offering no further technical details, exploit information, or mitigation guidance.

    0000038
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28211 The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log … https://www.cve.org/CVERecord?id=CVE-2026-28211

    Post summary

    The text merely references CVE‑2026‑28211 with a brief statement of vulnerability existence, providing no additional technical, exploit, or patch details.

    00000149
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28211 Arbitrary Code Execution in NVDA Dev & Test Toolbox Log Reader Feature https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28211

    Post summary

    The post announces CVE-2026-28211, identifying an arbitrary code execution flaw in NVDA's Dev & Test Toolbox Log Reader, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000040
    4.0K followersView on X

Explore more