SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86185

HIGH · CVSS 8 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Bilibili Desktop versions up to 1.18.0 are vulnerable due to the disabling of TLS certificate verification, allowing attackers in an on-path position to intercept configuration fetches and inject malicious JavaScript. This exploitation can lead to unauthorized execution of system commands and theft of sensitive information, such as login credentials. Organizations using this application should prioritize remediation to mitigate the risk of potential data breaches and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86185
Severity
HIGH
CVSS
8
EPSS
0.11%
Java

Original NVD Description

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.