CVEFinder.io

CVE-2026-35093

âš ī¸ high
🔍 Scan for this CVE
Summary

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

CVSS Score
8.8
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-04-01
First Seen: 2026-04-08
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 81.1% of all 318,071 vulnerabilities in our database.

#60,199
Top 25% most severe
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Apr 3, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank Koen Tange (monokles.eu) for reporting this issue.
SSVC data provided by CISA
Last Modified 2026-04-07
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 4

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-35094 â„šī¸ low 3.3 0.0 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... 2026-04-01
CVE-2023-4134 đŸ”ļ medium 5.5 0.0 A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device... 2024-11-14
CVE-2024-3056 âš ī¸ high 7.7 0.4 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... 2024-08-02
CVE-2024-6290 âš ī¸ high 8.8 0.3 Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... 2024-06-24
CVE-2024-6291 âš ī¸ high 8.8 0.2 Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit ... 2024-06-24
CVE-2024-6292 âš ī¸ high 8.8 0.3 Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... 2024-06-24
These CVEs affect the same products