CVE-2026-5656 - Vulnerability Analysis
HighCVSS: 7.0Last Updated: May 1, 2026
Wireshark - Path Traversal
Published: May 1, 2026Updated: May 1, 2026PoC Available
Overview
Wireshark 4.4.0 to 4.4.14 and 4.6.0 to 4.6.4 contain a path traversal caused by improper profile import path validation, letting attackers cause denial of service and possible code execution, exploit requires crafted profile import.
Severity & Score
Severity: High
CVSS Score: 7.0
Impact
Attackers can cause denial of service and potentially execute code via crafted profile import.
Mitigation
Update to a version later than 4.6.4 or 4.4.14.
References
Related Resources
Details
- CVE ID
- CVE-2026-5656
- Severity
- High
- CVSS Score
- 7.0
- Type
- path_traversal
- Status
- confirmed
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H