OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102875

HIGH · CVSS 7.8 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

VLC media player versions prior to 3.0.24 are susceptible to a path traversal vulnerability in the skins2 ThemeLoader, allowing attackers to exploit improperly validated member names in .vlt skin archives. This flaw enables the creation of malicious skin files that can write arbitrary files with the same privileges as the VLC user, potentially leading to code execution via Lua script injection. Organizations using VLC media player should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102875
Severity
HIGH
CVSS
7.8
EPSS
0.17%

Original NVD Description

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.