
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20348 is a memory corruption vulnerability in the XAR file format parser of ClamAV, classified as a ClamAV XAR File Format Processing Memory Corruption Vulnerability. It allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition — and potentially other expanded impacts — by submitting a crafted XAR file for scanning. The vulnerability affects Cisco Secure Endpoint Connector for Linux (before 1.29.2), macOS (before 1.27.4), and Windows (before 8.6.3 and before 7.5.24.21780 for the 7.x branch). It was publicly disclosed on August 7, 2026, with a patch advisory updated through August 13, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper boundary checks when processing content in XAR archive files during ClamAV scanning, classified as CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow). When ClamAV parses a maliciously crafted XAR file, the lack of proper size validation can lead to memory corruption, causing the scanning process to crash. The attack vector is fully remote and requires no authentication, no user interaction, and no special privileges — an attacker simply needs to submit a crafted XAR file to a system running a vulnerable ClamAV instance. On Windows platforms, the ClamAV scanning process runs in a privileged security context, elevating the Security Impact Rating to High; on Linux and macOS, the process runs with lower privileges, resulting in a Medium SIR (Cisco Advisory). The vulnerability was reported by researcher "leduckhuong" (Cisco Advisory).
Successful exploitation causes the ClamAV scanning process to terminate, resulting in a DoS condition that interrupts all file scanning operations on the affected device. There is no confirmed confidentiality or integrity impact under normal exploitation; however, Cisco notes the possibility of "other expanded impacts" due to the underlying memory corruption. On Windows-based Cisco Secure Endpoint deployments, the elevated privilege context of the scanning process increases the potential severity. Disruption of endpoint scanning could allow malware to go undetected during the outage window, indirectly increasing organizational risk (Cisco Advisory, GitHub Advisory).
As of the advisory date, Cisco PSIRT is not aware of any proof-of-concept (PoC) exploit code specifically for CVE-2026-20348, nor any malicious in-the-wild exploitation. (Note: PoC code is publicly available for two related vulnerabilities in the same advisory — CVE-2026-20337 and CVE-2026-20338 — but not for CVE-2026-20348.) The EPSS score is approximately 0.327%, placing it in the 26th percentile for exploitation probability within 30 days. The vulnerability is automatable (no user interaction required), which lowers the barrier for exploitation if a PoC were to emerge. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Cisco Advisory, GitHub Advisory).
clamdscan or the clamd socket).clamd, clamscan, or the Cisco Secure Endpoint connector scanning component); repeated process restarts in a short time window..xar files in directories monitored by ClamAV or submitted to scanning endpoints; core dump files generated by the ClamAV process.Cisco has released fixed versions for all affected Secure Endpoint Connector platforms: Linux 1.29.2, macOS 1.27.4, and Windows 8.6.3 / 7.5.24.21780. Cisco explicitly states there are no workarounds available for this vulnerability. Depending on the configured policy, Cisco Secure Endpoint Connector may update automatically; otherwise, updated releases are available through the Cisco Secure Endpoint portal. As interim risk reduction, administrators may consider implementing network controls to restrict which systems can submit files to ClamAV for scanning, and deploying automated process restart mechanisms to minimize downtime if exploitation occurs (Cisco Advisory).
Cisco's advisory for the broader ClamAV vulnerability set (August 2026) received notable coverage from security media, with outlets including SecurityWeek, Security Affairs, GBHackers, and CyberSecurityNews reporting on the seven ClamAV flaws — highlighting that two of the related CVEs (CVE-2026-20337 and CVE-2026-20338) have public PoC code available. Field Effect published a blog specifically noting the public PoC availability for the ClamAV vulnerability set. The Hacker News included the ClamAV flaws in its weekly recap. Community discussion noted the elevated risk on Windows platforms due to the privileged scanning context, and the broader concern that PoC availability for related CVEs could accelerate exploitation attempts across the vulnerability family (SecurityWeek, Security Affairs, Field Effect).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."