CVE-2026-34458
A vulnerability in Sandboxie-Plus allows a local user to inject malicious commands into the software's configuration file. This flaw occurs because the software fails to properly check authorization or sanitize certain inputs used to update settings.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Sandboxie-Plus version 1.17.2 or earlier on Windows.
Real-world impact
An attacker with standard user access on a Windows machine could bypass security restrictions and escalate their privileges to SYSTEM level, effectively taking full control of the computer.
Why this severity
The critical score reflects that an attacker can achieve full control over the system (SYSTEM privileges) by exploiting a flaw that requires only local access and minimal effort.
What to do about it
- 01Upgrade Sandboxie-Plus to version 1.17.3 or later.
NVD-referenced vendor advisory
Timeline
- May 5, 2026 · May 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/sandboxie-plus/Sandboxie/re…patchrelease notes
- github.com/sandboxie-plus/Sandboxie/se…exploitvendor advisory