CVE-2026-28373Disclosure(apple / macos)

MEDIUMCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apple macos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos
  • stackfield
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
macosstackfieldwindows

1 version affected across 3 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-25: 3Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1PoC Mentioned / Linked · 2026-03-25: 1Exploit Tool / Code · 2026-03-25: 1Technical Details · 2026-03-25: 3Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 103-2504-0304-04
Signal classification2 categories
Disclosure
480.0%
PoC
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-253
Disclosure2PoC1
2026-04-031
Disclosure1
2026-04-041
Disclosure1
Full discourse5 posts
  • Julien | MrTuxracer 🇪🇺@MrTuxracer
    PoC

    I turned an encrypted backup into RCE in the Stackfield desktop app via a path traversal and an arbitrary file write (CVE-2026-28373)🥷 #security https://www.rcesecurity.com/2026/03/stackfield-desktop-app-rce-via-path-traversal-and-arbitrary-file-write-cve-2026-28373/

    Post summary

    The post presents a proof‑of‑concept demonstrating remote code execution in the Stackfield desktop app by exploiting a path traversal and arbitrary file write; it does not claim active exploitation or provide a patch.

    2151115709.0K
    38.6K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373) https://www.rcesecurity.com/2026/03/stackfield-desktop-app-rce-via-path-traversal-and-arbitrary-file-write-cve-2026-28373/

    Post summary

    The post announces a new remote code execution vulnerability (CVE-2026-28373) in Stackfield Desktop App, detailing that it exploits path traversal and arbitrary file writes, and links to a related security article.

    01022508
    32.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28373 - Critical The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicio... https://www.thehackerwire.com/vulnerability/CVE-2026-28373/ https://t.co/VpNf3fKXJq

    Post summary

    The tweet announces that Stackfield Desktop App versions prior to 1.10.2 are vulnerable to a path traversal flaw via the filePath property in decryption functions.

    0000055
    164 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28373 - Stackfield Desktop App Path Traversal Vulnerability Intel Report: https://ift.tt/BGxeVCE

    Post summary

    An alert announces CVE-2026-28373, a path traversal vulnerability in the Stackfield Desktop App, but provides no PoC, exploit, or mitigation details.

    0000051
    281 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373) https://www.rcesecurity.com/2026/03/stackfield-desktop-app-rce-via-path-traversal-and-arbitrary-file-write-cve-2026-28373/ https://t.co/J8caxgmgzA

    Post summary

    A new remote code execution vulnerability (CVE‑2026‑28373) in Stackfield Desktop App has been disclosed, detailing its path traversal and file write nature, but no PoC, exploit code, active exploitation, or patch information is included in the excerpt.

    0000080
    808 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSmicrosoftwindows---
Appstackfieldstackfield---

Explore more