CVEFinder.io

CVE-2026-35093

âš ī¸ high
🔍 Scan for this CVE
Summary

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

CVSS Score
8.8
High
EPSS Score
0.2
Exploit Probability
Published Date
2026-04-01
First Seen: 2026-04-08
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 80.8% of all 350,976 vulnerabilities in our database.

#67,387
Top 25% most severe
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Apr 3, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank Koen Tange (monokles.eu) for reporting this issue.
SSVC data provided by CISA
Last Modified 2026-07-15
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 4

🔗 References 4

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-54230 âš ī¸ high 7.0 0.2 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr... 2026-06-13
CVE-2026-54231 đŸ”ļ medium 5.5 0.2 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script... 2026-06-13
CVE-2026-50292 âš ī¸ high 7.4 0.3 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti... 2026-06-04
CVE-2026-35094 â„šī¸ low 3.3 0.0 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... 2026-04-01
CVE-2023-4134 đŸ”ļ medium 5.5 0.0 A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device... 2024-11-14
CVE-2024-3056 âš ī¸ high 7.7 0.4 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... 2024-08-02
These CVEs affect the same products