Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
Summary
| CVE | CVE-2026-8993 |
|---|---|
| State | PUBLISHED |
| Assigner | SK-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-02 12:16:18 UTC |
| Updated | 2026-06-02 14:50:37 UTC |
| Description | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.000330000 probability, percentile 0.099330000 (date 2026-06-04)
Problem Types: CWE-74 | CWE-200 | CWE-74 CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | CWE-1395 CWE-1395: Dependency on Vulnerable Third-Party Component
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ditec A.s. | D.Launcher 2 | affected 2.0.7 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.slovensko.sk/sk/oznamy/detail/_zranitelnost-aplikacie-d-launc | [email protected] | www.slovensko.sk | |
| ditec.sk/static/kep/apps/release-notes/en | [email protected] | ditec.sk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Martin Orem from Binary House (en)
There are currently no legacy QID mappings associated with this CVE.