PT-2026-44400 · Notepad++ · Notepad++

Published

2026-05-26

·

Updated

2026-05-31

·

CVE-2026-48778

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.6.1
Description A flaw in the config.xml configuration file occurs due to improper neutralization of special elements when processing the commandLineInterpreter parameter. This can allow an attacker to execute arbitrary code.
Recommendations Update to version 8.9.6.1.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-07493
CVE-2026-48778

Affected Products

Notepad++