CVE-2026-20346
Clam AntiVirus vulnerability analysis and mitigation

Overview

CVE-2026-20346 is a memory corruption vulnerability in the PDF file format parser of ClamAV, classified as ClamAV PDF File Format Processing Memory Corruption. It allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition — and potentially other expanded impacts — by submitting a crafted PDF file for scanning. The vulnerability affects ClamAV as bundled in Cisco Secure Endpoint Connector for Windows (prior to 8.6.3/7.5.24.21780), Linux (prior to 1.29.2), and Mac (prior to 1.27.4); Cisco Secure Endpoint Private Cloud is not directly affected. It was publicly disclosed on August 7, 2026, with a patch advisory updated through August 13, 2026. The CVSS v3.1 base score is 7.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is improper boundary checks when processing content in PDF files during ClamAV scanning, classified as CWE-125 (Out-of-bounds Read). When ClamAV parses a specially crafted PDF, it reads data beyond the intended buffer boundary, resulting in memory corruption that causes the scanning process to crash. The attack vector is network-based, requires no authentication, no privileges, and no user interaction — making it fully automatable. The vulnerability was reported by Tristan Madani from Talence Security and tracked under Cisco Bug ID CSCwu65985 (Cisco Advisory).

Impact

Successful exploitation terminates the ClamAV scanning process, resulting in a DoS condition that disrupts antivirus scanning operations on the affected device. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the potential for expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no confirmed confidentiality or integrity impact at this time, though Cisco notes the possibility of "other expanded impacts as a result of memory corruption" (Cisco Advisory).

Exploitability

As of the advisory, Cisco PSIRT is not aware of proof-of-concept (PoC) exploit code specifically for CVE-2026-20346, nor any malicious exploitation in the wild. However, a Field Effect blog post published after the initial advisory indicates that public PoC code became available for related ClamAV vulnerabilities in this advisory batch (Field Effect Blog). The vulnerability is automatable (no user interaction required), which increases risk. The EPSS score is approximately 0.327% (26th percentile), and there is no current CISA KEV catalog listing for this CVE (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify systems running ClamAV or Cisco Secure Endpoint Connector that scan externally submitted files (e.g., email gateways, web proxies, file upload services using ClamAV for scanning).
  2. Craft malicious PDF: Create a PDF file with malformed content that triggers improper boundary checks in ClamAV's PDF parser, causing an out-of-bounds buffer read during scanning.
  3. Submit crafted file: Deliver the crafted PDF to the target system through any channel that triggers ClamAV scanning — such as email attachment, file upload to a web application, or direct submission to a scanning API endpoint.
  4. Trigger crash: ClamAV's PDF parser reads beyond the intended buffer boundary, causing memory corruption and terminating the ClamAV scanning process.
  5. Achieve DoS: The ClamAV scanning service crashes, resulting in a denial of service condition — potentially disabling antivirus protection on the affected host until the service is restarted or patched (Cisco Advisory).

Indicators of compromise

  • Logs: Unexpected ClamAV process termination events in system logs (e.g., clamd crash entries in /var/log/syslog or Windows Event Viewer); repeated scanning failures or error messages referencing PDF file processing.
  • Process: Sudden termination of the clamd or ClamAV scanning process without administrator action; automatic service restart events for ClamAV/Cisco Secure Endpoint Connector.
  • File System: Presence of crafted or anomalous PDF files in directories monitored by ClamAV (e.g., mail spool, upload directories) that consistently trigger scanner crashes.
  • Network: Repeated submission of PDF files from the same external source to scanning endpoints, particularly if correlated with ClamAV service crashes.

Mitigation and workarounds

Cisco has released fixed versions for all affected Secure Endpoint Connector platforms: Linux — version 1.29.2 (Bug ID CSCwv87285); Mac — version 1.27.4 (Bug ID CSCwv87286); Windows — version 8.6.3/7.5.24.21780 (Bug ID CSCwv87283). Updated connectors are available through the Cisco Secure Endpoint portal and may update automatically depending on configured policy. There are no workarounds available for this vulnerability. As a temporary measure until patching is possible, consider restricting PDF file submissions to ClamAV scanning or implementing additional input validation upstream. Cisco Secure Endpoint Private Cloud customers should monitor Bug ID CSCwv91588 for connector update availability (Cisco Advisory).

Community reactions

Cisco's PSIRT published the advisory on August 7, 2026, covering seven ClamAV vulnerabilities affecting Cisco Secure Endpoint, with CVE-2026-20346 among them. Security news outlets including GBHackers, CyberSecurityNews, and IT Security News covered the broader advisory, highlighting the risk of remote attackers crashing antivirus scanning with crafted files (GBHackers, CyberSecurityNews). Field Effect published a notable follow-up blog noting that public PoC code became available for some vulnerabilities in this advisory group (Field Effect Blog). The Hacker News included the ClamAV vulnerabilities in its weekly recap, and Linuxiac covered the ClamAV 1.5.4 release that addressed eight security vulnerabilities (Linuxiac).

Additional resources


SourceThis report was generated using AI

Related Clam AntiVirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20348HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20347HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20346HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20345HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-70622HIGH7.1
  • Clam AntiVirus logoClam AntiVirus
  • rust-cargo-c
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management