CVE-2026-20345
Clam AntiVirus vulnerability analysis and mitigation

Overview

CVE-2026-20345 is a stack-based buffer overflow vulnerability in the GPT file format parser of ClamAV, classified as ClamAV GPT File Format Processing Memory Corruption. It allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition or potentially other expanded impacts due to memory corruption. The vulnerability affects ClamAV as bundled with Cisco Secure Endpoint Connector for Windows (prior to 8.6.3/7.5.24.21780), Linux (prior to 1.29.2), and Mac (prior to 1.27.4). It was publicly disclosed on August 7, 2026, with a patch released on August 13, 2026. The CVSS v3.1 base score is 7.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is improper handling of an endian conversion operation in ClamAV's GPT file format parser, classified as CWE-121 (Stack-based Buffer Overflow). The flawed endian conversion can result in an out-of-bounds buffer write to the stack, leading to memory corruption. An attacker exploits this by submitting a specially crafted GPT (GUID Partition Table) file to a ClamAV-enabled scanning endpoint — no authentication or user interaction is required. CVE-2026-20345 was reported by researchers from the Atuin Automated Vulnerability Discovery Engine and Tianchu Chen of Tencent Xuanwu Lab (Cisco Advisory).

Impact

Successful exploitation causes the ClamAV scanning process to terminate, resulting in a DoS condition that disrupts antivirus scanning operations. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the risk of expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no evidence of confidentiality or integrity impact at this time, but the advisory notes the possibility of "other expanded impacts" from the underlying memory corruption (Cisco Advisory).

Exploitability

No public proof-of-concept (PoC) exploit code is known for CVE-2026-20345 specifically; Cisco PSIRT confirmed PoC code exists only for CVE-2026-20337 and CVE-2026-20338 within the same advisory. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.327%, indicating a low near-term exploitation probability. The vulnerability is automatable (no user interaction required) and exploitable over the network without credentials, making it a candidate for opportunistic targeting if a PoC emerges (Cisco Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify systems running Cisco Secure Endpoint Connector (Windows, Linux, or Mac) with ClamAV scanning enabled, using network scanning tools or service banners to confirm vulnerable versions prior to the fixed releases.
  2. Craft malicious GPT file: Construct a specially crafted GPT (GUID Partition Table) file that triggers the improper endian conversion in ClamAV's GPT parser, causing an out-of-bounds write to the stack.
  3. Submit file for scanning: Deliver the crafted GPT file to the target system through any channel that causes ClamAV to scan it — such as email attachment, file share, web upload, or direct file placement on a monitored directory.
  4. Trigger crash: When ClamAV processes the malicious GPT file, the stack-based buffer overflow corrupts memory, causing the ClamAV scanning process to terminate and resulting in a DoS condition (Cisco Advisory).

Indicators of compromise

  • Logs: Unexpected termination or crash entries for the ClamAV scanning process (e.g., clamd or Cisco Secure Endpoint scanning service) in system logs or application event logs; crash dump files generated by the ClamAV process.
  • Process: Sudden absence or repeated restarts of the ClamAV/Cisco Secure Endpoint scanning process; Windows Event Log entries (Event ID 1000/1001) indicating application crashes for the Secure Endpoint connector.
  • File System: Presence of unexpected GPT-formatted files in directories monitored by ClamAV, particularly files with anomalous partition table structures or unusual file sizes for GPT content.
  • Network: Unusual inbound file submissions to mail gateways, web proxies, or file shares containing GPT-format files from external or untrusted sources, especially in high volume.

Mitigation and workarounds

Cisco has released fixed versions to address this vulnerability: Secure Endpoint Connector for Windows version 8.6.3/7.5.24.21780, for Linux version 1.29.2, and for Mac version 1.27.4. Updated connectors are available through the Cisco Secure Endpoint portal and may update automatically depending on configured policy. There are no workarounds available; upgrading to a fixed release is the only remediation. As an interim measure until patching is complete, administrators should implement network controls to restrict GPT file submissions to ClamAV scanners or disable GPT file scanning if not operationally required (Cisco Advisory).

Community reactions

SecurityWeek reported on the broader set of ClamAV vulnerabilities disclosed in this advisory, noting that two of the seven flaws (CVE-2026-20337 and CVE-2026-20338) have public PoCs, which elevated community concern (SecurityWeek). Security Affairs and CyberSecurityNews also covered the advisory, highlighting the risk to Cisco Secure Endpoint installations (Security Affairs, CyberSecurityNews). Field Effect published a blog noting the availability of public PoC for related CVEs and advising prompt patching (Field Effect). The Linuxiac community noted the ClamAV 1.5.4 release addressing eight security vulnerabilities, including this flaw (Linuxiac).

Additional resources


SourceThis report was generated using AI

Related Clam AntiVirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20348HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20347HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20346HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20345HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-70622HIGH7.1
  • Clam AntiVirus logoClam AntiVirus
  • rust-cargo-c
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management