CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.44%
- CWE
- CWE-522
- Published
- 2026-07-03
- Last modified
- 2026-09-15
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2026-32633 — Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
- CVE-2020-37097 — Edimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)
- CVE-2026-29128 — IDC SFX2100 Satellite Receiver bgpd/ospfd/ripd/zebra Config Credential Disclosure via World-Readable Files
- CVE-2025-13478 — Cache Misconfiguration Leading to Cross-User Data Exposure
- CVE-2026-82434 — Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
- CVE-2026-42869 — SOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC tools
- CVE-2026-56843 — Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo
- CVE-2026-9079 — stale proxy password leak