CVE-2026-4946 is a high-severity vulnerability affecting Ghidra versions prior to 12.0.3, where improper processing of annotation directives in auto-analyzed binary data can lead to arbitrary command execution. A crafted binary can present clickable text in the Ghidra UI which, when interacted with by an analyst, executes attacker-controlled commands on their machine, posing a significant risk to confidentiality, integrity, and availability (CVSS 8.8 HIGH). While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion, with recommendations for immediate upgrades to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 12.0.3CPE match | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.