Sploitus

CVE-2026-52886

1 known exploit for CVE-2026-52886

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, allowing parent-directory sequences during snapshot-mode restoration to read an arbitrary user-readable file outside the backup directory into an editor tab. This issue is fixed in version 8.9.7.

Affected products
Notepad++
CVSS 4.0
5.1 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-22
NVD status
Received
Published
2026-08-17
CVE-2026-52886 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-52886

Proof-of-concept code and exploit modules indexed by Sploitus