216.73.217.98

CVE-2026-34527

· Published 05/05/2026 20:16 · Modified 05/05/2026 20:16

Labels: CVE-2026-34527 2026-05-05CVE-2026-34527CWE-328[email protected]

Essential information

Published
05/05/2026 20:16
Modified
05/05/2026 20:16
Author
Creator
CVSS
2.0 LOW (v3) 2.0 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high nibble of each byte is shifted right by 8 instead of 4, which always produces zero for an 8-bit value. As a result, the stored EditPassword hash only preserves the low nibble of each digest byte, reducing the effective entropy from 160 bits to 80 bits. This is layered on top of an unsalted SHA-1 scheme. The reduced entropy makes leaked or backed-up password hashes materially easier to brute-force. This issue has been fixed in version 1.17.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sandboxie / sandboxie-plus cpe:2.3:a:sandboxie:sandboxie-plus:<1.17.3:*:*:*:*:*:*:*

References