CVE-2026-48831Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some parties feel that this is not a bug to be addressed in Wine, because there is no known solution that avoids a severe loss of usability (Wine could be a binfmt-misc handler, but binfmt-misc does not exist on all platforms supported by Wine).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-669

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-25: 205-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting WineHQ Wine (CVE-2026-48831) https://vuldb.com/vuln/365469

    Post summary

    The post announces a newly identified vulnerability in WineHQ Wine (CVE-2026-48831) with an increased severity rating, without providing technical details, PoC, or patch information.

    0000087
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-48831 Re https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48831 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet simply links to a CVE detail page without providing any substantial information on exploitation, patching, or technical specifics.

    0000086
    4.0K followersView on X

Explore more