GHSA-4vj5-vh2w-8g5j · Severity: high — In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate...
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
Conclusion & alert: CVE-2026-34352 is rated Low Risk (39.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.25%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.01% | 0.25% | +0.24% |
| 2 | 2026-03-27 | — | 0.01% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 3.1 | HIGH |
|
2.5 | 5.3 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-4vj5-vh2w-8g5j · Severity: high — In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-34352: 1 source package rows (tigervnc); 5 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 5. | https://security.alpinelinux.org/vuln/CVE-2026-34352 |
debian
|
not yet assigned | CVE-2026-34352 not yet assigned priority: Debian including 1 source packages (tigervnc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2026-34352 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2026-34352 |
suse
|
high | CVE-2026-34352 severity important: SUSE including 53 source package names (2.2.1-5.112:libpng16-16-1.6.43-slfo.1.1_4.1, latest:libpng16-16-1.6.43-slfo.1.1_4.1, …), 156 product×package rows across 51 product lines (Container suse/sl-micro/6.0/base-os-container, Container suse/sl-micro/6.1/base-os-container, … (51 product lines)): Fixed 151, First Fixed 5. | https://www.suse.com/security/cve/CVE-2026-34352/ |
ubuntu
|
medium | CVE-2026-34352 medium priority: Ubuntu including 1 source packages (tigervnc), 6 status rows across 6 suites (bionic, focal, jammy, noble, questing, upstream): needs-triage 6. | https://ubuntu.com/security/CVE-2026-34352 |
| URL | Tags |
|---|---|
| https://github.com/TigerVNC/tigervnc/commit/0b5cab169d847789efa54459a87659d3fd484393 | Patch |
| https://github.com/TigerVNC/tigervnc/issues/2079 | |
| https://groups.google.com/g/tigervnc-announce/c/anHL9WLshLI | Mailing List Patch |
| https://sourceforge.net/projects/tigervnc/files/stable/1.16.2 | Release Notes |
| https://www.openwall.com/lists/oss-security/2026/03/26/7 | Mailing List Third Party Advisory |