OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102674

HIGH · CVSS 8.2 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Electron applications prior to specified versions are vulnerable due to a flaw where windows opened from a sandboxed top-level document do not inherit the intended HTML sandbox restrictions, potentially exposing the application's full origin to untrusted content. This can lead to unauthorized access and manipulation of sensitive data, making it critical for developers using Electron to update to the patched versions. Organizations utilizing Electron for cross-platform desktop applications should prioritize this update to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102674
Severity
HIGH
CVSS
8.2
EPSS
0.27%
Windows Java

Original NVD Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.