PatchSiren

Newell Brands CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Newell Brands CVE published 2026-09-15

CVE-2026-76796

CVE-2026-76796 is a medium-severity vulnerability in the Newell Brands DYMO Connect Desktop local web service. The LoadImageAsPngBase64 endpoint accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. The issue was fixed in version 1.6.2, but the fix only limits access by file extension, not by di [truncated]