CVE-2026-48056
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate execu
CVSS
10.0
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-20 · CWE-749
Not enough EPSS history yet.
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20901——
———Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.9hCVE-2026-713904.0 MED—
———CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.9hCVE-2026-703255.5 MED—
———Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.5hCVE-2026-703235.5 MED—
———Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.8hCVE-2026-703225.5 MED—
———Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.8hCVE-2026-703205.5 MED—
———Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.5h