CVE-2026-4158Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads configuration from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of KeePassXC when run by a target user on the system. Was ZDI-CAN-29156.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-17); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Technical Details · 2026-03-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 103-1703-1804-1904-21
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-03-181
General1
2026-04-191
General1
2026-04-211
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-4158 KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privile… https://www.cve.org/CVERecord?id=CVE-2026-4158

    Post summary

    The text references a local privilege escalation vulnerability in KeePassXC related to OpenSSL configuration, but lacks PoC, exploit details, patch information, or active exploitation claims.

    01010167
    57.2K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-4158 (CVSS 7.3) KeePassXC OpenSSL config flaw allows local privilege escalation via uncontrolled search path. Impact: Arbitrary code execution in KeePassXC context Requires: Low-priv access + user interaction #CVE #Vulnerability #PatchNow https://t.co/gjN5fx0Wz9

    Post summary

    The tweet announces a high‑severity CVE-2026-4158 affecting KeePassXC with local privilege escalation, providing technical details but no PoC, exploit code, or indications of active exploitation.

    0000041
    26 followersView on X
  • Anonymous Tech@Anonymous_Tech7
    General

    KeePassXC installations are vulnerable to local privilege escalation via CVE-2026-4158, allowing attackers to gain elevated access after executing low-privileged code, with a CVSS rating of 7.3 assigned by ZDI.

    Post summary

    KeePassXC is vulnerable to CVE-2026-4158, a local privilege escalation with a CVSS score of 7.3.

    0000034
    1 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability (CVE-2026-4158) #CyberSecurity #KeePassXC #LocalPrivilegeEscalation #OpenSSL https://www.systemtek.co.uk/?p=48768 https://t.co/u1vB2ZsaFN

    Post summary

    The tweet announces the existence of CVE-2026-4158 for KeePassXC, noting an OpenSSL configuration issue that could lead to local privilege escalation, and provides a link for further details.

    0000056
    1.8K followersView on X

Explore more