HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11879Published Modified CNA INCIBE

CVE-2026-11879: Arbitrary code execution in MobaXterm Personal Edition (Portable)

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s secure paths, enabling an attacker with local access to place a specially crafted DLL to be executed automatically when the victim launches the application.

Metrics

CVSS v4.0
8.5
Severity
HIGH
Fixed in
26.4
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a DLL search-order hijacking vulnerability in MobaXterm Personal Edition (Portable) version 26.3. The application loads DLLs from a predictable, user-writable temporary directory at startup before checking secure system paths, meaning a local attacker with a low-privilege account can plant a malicious DLL that runs automatically when any user on the same host launches the application. Successful exploitation gives the attacker full code execution in the context of the launching user, enabling complete read, write, and control of that user's resources. A patched-image rebuild at version 26.4 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11879 is available across every HarborGuard environment; the CVE is ingested from upstream advisory feeds within minutes of publication and matched against customer images, including custom-built images that package MobaXterm Personal Edition (Portable). Any image containing the affected 26.3 build is flagged automatically.

Available
Triage

HarborGuard scores this issue at CVSS 8.5 HIGH based on the published v4.0 vector, and per-environment compliance policy weighting is available to escalate or suppress routing based on each organization's risk profile. Triage tickets are routable to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild at MobaXterm Personal Edition (Portable) version 26.4 becomes available on HarborGuard once the upstream fix is confirmed present in the base image. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run a regression test suite, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; no network access to the target system is required.

  • AuthenticationRequired

    Any low-privilege local account is sufficient; the attacker does not need administrative rights to write to the predictable temporary directory.

  • Victim interactionNot required

    No victim interaction beyond the target user's normal launch of MobaXterm is required; the malicious DLL executes automatically on startup.

  • Attack complexityDetail

    The exploit is reliable and condition-free; the temporary directory path is predictable and no race condition or special memory layout is needed.

Blast Radius

  • Reads files and secrets accessible to the launching user, including SSH keys, session credentials, and any data in the user's profile.
  • Writes or modifies files under the launching user's permissions, including stored session configurations and local application data.
  • Executes arbitrary code persistently in the user's session, enabling installation of backdoors or lateral movement tools.
  • Crashes or manipulates the MobaXterm process itself, disrupting terminal and tunneling sessions the user depends on.

How HarborGuard Handles This

Available on HarborGuard: images containing MobaXterm Personal Edition (Portable) 26.3 are detectable against this CVE immediately upon ingest. Where compliance policy permits, a rebuild against version 26.4 is available, and for customers who opt into auto-remediation, HarborGuard will perform the rebuild, run regression tests, and open a patch PR against affected workloads automatically. The median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Until a rebuild is confirmed deployed, customers can reduce exposure by restricting write access to the temporary directory used at MobaXterm startup via host-level file system policy, limiting which users share the same host as privileged operators, and applying least-privilege controls so untrusted local accounts cannot write to user-accessible temp paths.

See how HarborGuard automates this

Fix available

26.4
Patch commits
Affected packages
  • Mobatek / MobaXterm Personal Edition (Portable)
    26.3
    Fixed in 26.4
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References