CVE-2026-41527 Details
Description
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.
A local privilege escalation vulnerability has been identified in KDE Kleopatra versions prior to 26.08.0 on Windows. The issue arises from a flaw in the application's instance management mechanism, KUniqueService, which fails to properly restrict multiple instances from running simultaneously. This vulnerability allows local users to gain the privileges of the Kleopatra user.
Users are advised to update to KDE Kleopatra version 26.08.0 or later. If an immediate update is not possible, affected users should avoid running Kleopatra as an administrator and be cautious on Windows systems with untrusted users or software.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |