CVE-2026-76796
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
15/09/2026
Last modified:
22/09/2026
Description
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension only, not by directory - arbitrary-location reads of files with an allowed image extension remain possible by design (accepted residual risk).
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
4.00
Severity 3.x
MEDIUM


