CVE-2026-35207 affects the plugin-deepinid component in dde-control-center (Deepin Desktop Environment's control panel), with versions prior to 6.1.80 and 5.9.9 vulnerable to attack. The flaw stems from improper TLS certificate verification when the plugin fetches user avatars from openapi.deepin.com and other providers, allowing attackers to intercept and manipulate avatar downloads. The vulnerability carries a CVSS 3.1 score of 5.4 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction. An unauthenticated man-in-the-middle attacker could replace legitimate avatars with malicious or misleading images, potentially compromising user identity and creating social engineering opportunities. The impact is limited to confidentiality and integrity violations with no availability disruption. Exploitation status indicates this is not actively exploited in the wild, with no evidence of public exploit code or significant community attention. The EPSS score of 0.00017 reflects minimal real-world exploitation probability. Organizations using affected versions should prioritize patching to dde-control-center 6.1.80 or 5.9.9 to remediate this MITM vulnerability, though the current threat level remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linuxdeepin | Dde-Control-Center | >= 5.5.3, < 5.9.9, >= 6.1.35, < 6.1.80CNA affected | |
| Linuxdeepin | Deepin-Deepinid-Plugin | >= 2.0.1, <= 2.0.9CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.