CVE-2026-34352Patch(tigervnc / tigervnc)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch tigervnc tigervnc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tigervnc

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-04-14)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
tigervnc

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-04-14: 4Patch / Workaround · 2026-04-14: 4Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 1Technical Details · 2026-04-14: 103-2603-2704-14
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-271
Disclosure1
2026-04-144
Patch4
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34352 In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorre… https://www.cve.org/CVERecord?id=CVE-2026-34352

    Post summary

    The text announces a vulnerability in TigerVNC prior to version 1.16.2 that allows other users to observe or manipulate screen contents, or cause a crash.

    01010160
    56.9K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Someone on your server could be watching your screen right now. That's CVE-2026-34352. Here's how to check, patch, and block it on any Linux distro – Ubuntu, Rocky, or SUSE. Bash script + AppArmor included. Read more: 👉 https://tinyurl.com/3fecmhhk #SUSE https://t.co/WJxwfKFszZ

    Post summary

    The tweet promotes mitigation steps for CVE‑2026‑34352, offering a bash script with AppArmor rules and a link for more information, without describing any exploit or evidence of active attacks.

    0001060
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 TigerVNC permission flaw (CVE-2026-34352) – patch today. But patches expire. Evergreen fixes: ✅ Check commands (Ubuntu/Rocky Linux/SUSE) ✅ Bash automation script ✅ iptables fallback Read more: 👉https://tinyurl.com/2f7csd6 #SUSE #Securtity https://t.co/bmlzYy1wIn

    Post summary

    The tweet announces that the TigerVNC permission flaw (CVE‑2026‑34352) is patched today, providing Evergreen fix commands for Ubuntu, Rocky Linux, and SUSE, a Bash automation script, and iptables fallback, with a link for further details.

    0001050
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    TigerVNC just fixed a nasty bug: other users on the same server could watch your screen or inject fake keystrokes (CVE-2026-34352). Here's how to check if YOU are vulnerable on Ubuntu, Rocky, or #SUSE Read more: 👉 https://tinyurl.com/8c5j6dkf #Security https://t.co/yHk0lBq9AU

    Post summary

    The tweet announces that TigerVNC has released a patch for CVE-2026-34352, which allows users to view screens or inject keystrokes, and advises users on how to verify their vulnerability status.

    0001052
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    That TigerVNC permission bug (CVE-2026-34352) lets other users watch your screen. Fix it today with a script + iptables. But to *really* stop this class of flaw forever? Read more: 👉 https://tinyurl.com/3cz3vwrk #SUSE #Security https://t.co/BdFHUUwInX

    Post summary

    The tweet focuses on providing a script-based workaround to mitigate the TigerVNC permission bug (CVE‑2026‑34352).

    0001052
    1.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34352: HIGH] In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.#cve,CVE-2026-34352,#cybersecurity https://cvefind.com/CVE-2026-34352

    Post summary

    The tweet announces CVE‑2026‑34352 as a high‑severity permission flaw in TigerVNC that permits users to view or alter screen contents and potentially crash the application.

    0000044
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34352 - High In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions. https://www.thehackerwire.com/vulnerability/CVE-2026-34352/ https://t.co/F1SOnrafY4

    Post summary

    The tweet announces a high‑severity vulnerability in TigerVNC that permits unauthorized screen observation or manipulation due to incorrect permissions, with a brief technical description and a reference link.

    0000049
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptigervnctigervnc---

Explore more