CVE-2026-86185CWE-295

CVE-2026-86185

High · published September 5, 2026

CVSS v3.1
8.0
EPSS
In the wild
Unconfirmed
What it is

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.

The record
Technical detail
CVSS v3.1
8.0 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
8.6 · CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-295 · Improper Certificate Validation
Published
2026-09-05T16:16Z
References (4)
Timeline
  • 05 SEP 11:38Z
    Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification Bypass
    cvelistv5