Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-7840— UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)

CVSS 9.8 · Critical EPSS 1.58% · P73

Affected Version Matrix 1

VendorProductVersion RangeStatus
uvncUltraVNC≤ 1.8.2.2affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-7840

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
Source: CVE Program / CVE List V5
Vulnerability Description
UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via unchecked sprintf calls. The HTTP receive buffer accepts URIs up to approximately 150 KB (WI_RXBUFSIZE = 153600), so an unauthenticated attacker who can reach the repeater HTTP port (default TCP 80) can overflow hdrbuf by at least 500 bytes with a single HTTP request containing a URI of 1500 bytes or longer, corrupting adjacent .bss-segment globals. The overflow occurs before any authentication check, making it reachable without credentials. A remote, unauthenticated attacker can achieve arbitrary code execution on the host running the repeater.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
UltraVNC 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
uvnc UltraVNC是uvnc个人开发者开源的一款Windows远程控制软件。 UltraVNC 1.8.2.2及之前版本存在缓冲区错误漏洞,该漏洞源于嵌入式HTTP管理服务器中存在全局缓冲区溢出,函数wi_senderr()和wi_replyhdr()通过未检查的sprintf调用将调用者提供的HTTP请求URI写入固定1000字节的全局缓冲区hdrbuf,可能导致未经身份验证的攻击者通过发送长度至少1500字节的URI的HTTP请求溢出hdrbuf至少500字节,破坏相邻的.bss段全局变量,从
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
uvncUltraVNC 0 ~ 1.8.2.2 -

II. Public POCs for CVE-2026-7840

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 6843 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-7840

登录查看更多情报信息。

News Coverage for CVE-2026-7840 (1)

Vendor Pages for CVE-2026-7840 (1)

Same Patch Batch · uvnc · 2026-07-01 · 10 CVEs total

CVE-2026-78399.1 CRITICALUltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin ac
CVE-2026-78388.8 HIGHUltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason
CVE-2026-78317.5 HIGHUltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
CVE-2026-78307.4 HIGHUltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential
CVE-2026-78297.2 HIGHUltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token
CVE-2026-78285.3 MEDIUMUltraVNC repeater integer overflow in win_log malloc leading to heap overflow
CVE-2026-440404.8 MEDIUMUltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge b
CVE-2026-440414.3 MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated
CVE-2026-440423.7 LOWUltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check

IV. Related Vulnerabilities

V. Comments for CVE-2026-7840

No comments yet


Leave a comment