MEDIUM
Newell Brands
CVE published 2026-09-15
CVE-2026-76796
CVE-2026-76796 is a medium-severity vulnerability in the Newell Brands DYMO Connect Desktop local web service. The LoadImageAsPngBase64 endpoint accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. The issue was fixed in version 1.6.2, but the fix only limits access by file extension, not by di [truncated]