CVE-2026-8993 Details
Description
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.
A vulnerability has been identified in the D.Launcher 2 component of the Slovak eID client ecosystem, specifically in versions prior to 2.0.7.0. This vulnerability involves improper processing of custom URL handlers, which could be exploited to initiate NTLM authentication or SMB connections to an attacker's infrastructure, facilitating Server Side Request Forgery (SSRF) attacks. Exploitation requires user interaction, as the victim must open a specially crafted URL.
Users are advised to update to D.Launcher 2 version 2.0.7.0, available on the Slovensko.sk portal in the 'Na stiahnutie' section.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 2, 2026CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ditec.sk/static/kep/apps/release-notes/en | [email protected] | Release Notes |
| https://www.slovensko.sk/sk/oznamy/detail/_zranitelnost-aplikacie-d-launc | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| D.Launcher 2 | < 2.0.7.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | New CVE Received | [email protected] |
Volerion