CVE-2026-8148Disclosure(navercorp / mybox)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mybox

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mybox

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 105-0805-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure2
2026-05-091
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8148 NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privi… https://www.cve.org/CVERecord?id=CVE-2026-8148

    Post summary

    The post announces a local privilege‑escalation vulnerability (CVE‑2026‑8148) in NAVER MYBOX Explorer with technical details but no evidence of exploitation, PoC, or patch information.

    00010183
    57.5K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔥 Two fresh bugs to watch: CVE-2026-8149 affects BC-FJA BC-FIPS on Linux x86_64/AVX/AVX-512f in gcm128w and gcm512w (2.1.0 through 2.1.2), while CVE-2026-8148 lets a local attacker escalate to SYSTEM in NAVER MYBOX Explorer for Windows before 3.0.11.160 via registry manipulation. https://nvd.nist.gov/vuln/detail/CVE-2026-8149 https://nvd.nist.gov/vuln/detail/CVE-2026-8148 #CVE #CyberSecurity #Infosec #Vulnerability #Linux #Windows #PrivilegeEscalation

    Post summary

    Two new vulnerabilities—CVE-2026-8149 affecting Linux BC‑FJA BC‑FIPS GCM functions, and CVE-2026-8148 enabling local privilege escalation in NAVER MYBOX Explorer—have been announced without any evidence of exploitation or remediation.

    0001076
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8148 Local Privilege Escalation in NAVER MYBOX Explorer for Windows Before 3.0.11.160 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8148

    Post summary

    The entry announces the discovery of a Local Privilege Escalation vulnerability in NAVER MYBOX Explorer prior to version 3.0.11.160, with a link to detailed information but no PoC, exploit tool, active exploitation, patch, or false-positive claim.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnavercorpmybox-windows-

Explore more