CVE-2026-36365
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
May 04, 2026
Vendor
unknown
Description
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp
References
- https://github.com/Lymphatus/caesium-image-compressor
- https://github.com/Lymphatus/caesium-image-compressor/blob/main/src/utils/PostCompressionActions.cpp
- https://github.com/Lymphatus/caesium-image-compressor/pull/376
- https://github.com/mertsatilmaz/vulnerability-research/blob/main/advisories/CVE-2026-36365.md