CVE-2026-80432 | Kovid Goyal Kitty up to 0.48.x Drag/Drop Protocol kitty/dnd.c drop_enqueue_request/drop_left_child authorization
A vulnerability was found in Kovid Goyal Kitty up to 0.48.x. It has been declared as problematic. Impacted is the function drop_enqueue_request/drop_left_child of the file kitty/dnd.c of the component Drag/Drop Protocol. Such manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-80432. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More