PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11879 Mobatek CVE debrief

CVE-2026-11879 is a HIGH-severity vulnerability in MobaXterm Personal Edition (Portable) version 26.3 (Build 5154). The vulnerability allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s secure paths, enabling an attacker with local access to place a specially crafted DLL to be executed automatically when the victim launches the application.

Vendor
Mobatek
Product
MobaXterm Personal Edition (Portable)
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of MobaXterm Personal Edition (Portable) version 26.3 (Build 5154) should apply the necessary patches or updates to prevent arbitrary code execution.

Technical summary

The vulnerability has a CVSS score of 8.5 and is classified as HIGH severity. The CVSS vector is CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

HIGH

Recommended defensive actions

  • Apply the necessary patches or updates to MobaXterm Personal Edition (Portable) version 26.3 (Build 5154) to prevent arbitrary code execution.
  • Use secure coding practices and ensure that the application is configured to use secure paths for loading DLLs.

Evidence notes

The vulnerability was reported by Incibe and is tracked under CWE-427.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11879 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11879

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11879 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11879

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-mobateks-mobaxterm-personal-edition-portable

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.