CVE-2026-6861
CWE-193Published: April 22, 2026· Updated: Apr 22, 2026
Official Description
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Technical Analysis
CVE-2026-6861 requires local access, meaning attackers must already have a foothold on the target system.
Exploitation does not require any privileges, though user interaction (Required) is needed, which slightly reduces the risk of mass automated attacks.
A successful exploit results in availability disruption (denial of service), with a CVSS base score of 6.1.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (2)
Quick Facts
Related CVEs (CWE-193)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-6861 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts