CVE-2026-93534
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdate
CVSS
6.3
Medium
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Published: Sep 18, 2026 · Last modified: Sep 18, 2026 · CWE-494
0.2%EPSS · 30 days0.2%
2026-09-192026-09-21
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.
- github.comhttps://github.com/spatie/scotty/
- github.comhttps://github.com/spatie/scotty/commit/4b4e11bfc98e3a2159bb2b3d9b040293fcc44744
- github.comhttps://github.com/spatie/scotty/issues/21
- github.comhttps://github.com/spatie/scotty/releases/tag/1.4.3
- vuldb.comhttps://vuldb.com/cve/CVE-2026-93534
- vuldb.comhttps://vuldb.com/submit/943918
- vuldb.comhttps://vuldb.com/vuln/407451
- vuldb.comhttps://vuldb.com/vuln/407451/cti
- github.comhttps://github.com/spatie/scotty/issues/21
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-494507.1 HIG—
———Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded update's Authenticode signer with Joplin's signer. An attacker who controls the update delivery path can replace the update metadata and installer, and the client accepts an installer signed by another publisher or left unsigned after the user approves installation. Successful exploitation runs attacker-controlled code with the user's privileges and can compromise notes, credentials, and local data. This issue is fixed in version 3.7.2.13hCVE-2026-70067.3 HIG0.8%
——0Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypass cleanup, and have the elevated installer copy it into the protected installation directory, causing the DLL to execute in the context of any higher-privileged user who subsequently launches the application.4dCVE-2026-921287.5 HIG12.6%
——4Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.17hCVE-2026-636969.1 CRI25.6%
——8Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.6dCVE-2026-810526.8 MED3.8%
——1Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.6dCVE-2026-799637.4 HIG7.9%
——2Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.11d