CVE-2026-32810 affects the Halloy IRC application on *nix and macOS systems, where insecure default umask permissions allow local users to read plaintext credentials from configuration files. This medium-severity issue (CVSS 4.8) has a local attack vector and low complexity, leading to potential confidentiality compromise through the exposure of sensitive user credentials. The vulnerability impacts versions prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2026.4CPE matchmatch criteria | cpe:2.3:a:halloy:halloy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.