CVE-2026-34458Disclosure(sandboxie-plus / sandboxie)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandboxie.ini configuration file. The background service skips authorization checks for IPC messages targeting sections beginning with UserSettings_, but does not sanitize CRLF characters in either the value parameter (via MSGID_SBIE_INI_ADD_SETTING) or the setting name parameter (via MSGID_SBIE_INI_SET_SETTING). An attacker can inject a new sandbox section header with unrestricted permissions, enabling sandbox escape and SYSTEM privilege escalation. This issue has been fixed in version 1.17.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxie

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
sandboxie

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Technical Details · 2026-05-05: 305-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34458 INI Injection Vulnerability in Sandboxie-Plus 1.17.2 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34458

    Post summary

    The text announces an INI injection vulnerability in Sandboxie-Plus (up to version 1.17.2) and directs readers to a vulnerability details page.

    0000036
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34458 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard loca… https://www.cve.org/CVERecord?id=CVE-2026-34458 ----- Traducción: CVE-2026-34458 San… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-34458, a Sandboxie-Plus INI injection flaw affecting versions 1.17.2 and earlier, providing basic technical details but no PoC, exploit, patch, or active exploitation information.

    0000032
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34458 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard loca… https://www.cve.org/CVERecord?id=CVE-2026-34458

    Post summary

    The text announces an INI injection flaw in Sandboxie‑Plus (v1.17.2 and earlier) that allows local users to exploit the vulnerability, with no evidence of active exploitation or available patches.

    00000144
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsandboxie-plussandboxie---

Explore more