AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-48056

CRITICAL · CVSS 10 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Versions of the Streambert Electron Desktop App prior to 2.5.0 are vulnerable due to improper validation of executable paths in the run-download IPC handler, which allows a compromised renderer process to execute arbitrary local binaries with the application's privileges. This critical vulnerability (CVSS 10.0) poses a significant risk as it can lead to unauthorized code execution on affected systems. Organizations using Streambert should prioritize updating to version 2.5.0 or later to mitigate this severe security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48056
Severity
CRITICAL
CVSS
10
EPSS
0.38%

Original NVD Description

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.