In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
History

Fri, 27 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title Permission Misconfiguration Allows Unauthorized Access to Screen Content in TigerVNC TigerVNC: x0vncserver: TigerVNC x0vncserver: Information disclosure, data manipulation, and denial of service via incorrect permissions
Weaknesses CWE-279
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title Permission Misconfiguration Allows Unauthorized Access to Screen Content in TigerVNC

Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Tigervnc
Tigervnc tigervnc
Vendors & Products Tigervnc
Tigervnc tigervnc

Fri, 27 Mar 2026 04:00:00 +0000

Type Values Removed Values Added
Description In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-27T13:53:48.564Z

Reserved: 2026-03-26T22:30:46.508Z

Link: CVE-2026-34352

cve-icon Vulnrichment

Updated: 2026-03-27T13:28:53.233Z

cve-icon NVD

Status : Received

Published: 2026-03-26T23:16:20.903

Modified: 2026-03-26T23:16:20.903

Link: CVE-2026-34352

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-26T22:30:46Z

Links: CVE-2026-34352 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:22:56Z