SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91786

MEDIUM · CVSS 6.1 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in GNOME Shell allows a malicious remote search provider to exploit improper validation of icon dimensions, leading to an out-of-bounds read. This can result in the GNOME Shell process crashing, disrupting user sessions, and potentially exposing sensitive information from adjacent memory. Users and administrators of GNOME Shell should prioritize addressing this issue to mitigate risks to system stability and data confidentiality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91786
Severity
MEDIUM
CVSS
6.1
EPSS
0.13%

Original NVD Description

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.