CVE Explorer
CVE-2026-34527
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high nibble of each byte is shifted right by 8 instead of 4, which always produces zero for an 8-bit value. As a result, the stored EditPassword hash only preserves the low nibble of each digest byte, reducing the effective entropy from 160 bits to 80 bits. This is layered on top of an unsalted SHA-1 sch
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Sandboxie","vendor":"sandboxie-plus","versions":[{"status":"affected","version":"< 1.17.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f4110b096ef306da4559fa6a62d69a05c126fdb91299e0f063971e07a39a6b37 · sha256:73c98a9c6f7e0215… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":2,"baseSeverity":"LOW","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f4110b096ef306da4559fa6a62d69a05c126fdb91299e0f063971e07a39a6b37 · sha256:73c98a9c6f7e0215… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-328","description":"CWE-328: Use of Weak Hash","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f4110b096ef306da4559fa6a62d69a05c126fdb91299e0f063971e07a39a6b37 · sha256:73c98a9c6f7e0215… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-w37h-qm9p-h4x2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f4110b096ef306da4559fa6a62d69a05c126fdb91299e0f063971e07a39a6b37 · sha256:73c98a9c6f7e0215… · /containers/adp/0/references/0
{"name":"https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-w37h-qm9p-h4x2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-w37h-qm9p-h4x2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f4110b096ef306da4559fa6a62d69a05c126fdb91299e0f063971e07a39a6b37 · sha256:73c98a9c6f7e0215… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.