VYPR
High severity7.8NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026

CVE-2020-26893

CVE-2020-26893

Description

An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with ClamXAV 3's helper tool and perform privileged operations. This occurs because of inadequate client verification in the helper tool.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:clamxav:clamxav:*:*:*:*:*:*:*:*
    Range: >=3.0.0,<3.1.1
  • ClamXAV/ClamXAVdescription
  • ClamAV/Clamxavllm-fuzzy
    Range: <3.1.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.