Skip to main content
Vulnerability Database/CVE-2026-76796

CVE-2026-76796: DYMO Connect Path Traversal Vulnerability

CVE-2026-76796 is a path traversal flaw in DYMO Connect Desktop local web service that allows unauthorized file system access through inadequate path validation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-76796 Overview

CVE-2026-76796 is an arbitrary file read vulnerability in the Newell Brands DYMO Connect Desktop local web service. The LoadImageAsPngBase64 endpoint accepts a file path parameter without adequate validation. A crafted path allows a local attacker to read image files from arbitrary locations on the host filesystem, outside the intended scope. The issue is classified under CWE-73: External Control of File Name or Path. Newell Brands addressed the flaw in DYMO Connect Desktop version 1.6.2.

Critical Impact

A local attacker can invoke the DYMO Connect Desktop local web service to read arbitrary image files from disk. The vendor fix restricts access by file extension only, not directory, so reads of any file with an allowed image extension remain possible as accepted residual risk.

Affected Products

  • Newell Brands DYMO Connect Desktop for Windows (versions prior to 1.6.2)
  • Local web service component exposing the LoadImageAsPngBase64 endpoint
  • Endpoint hosts with the DYMO Connect Desktop application installed

Discovery Timeline

  • 2026-09-15 - CVE-2026-76796 published to the National Vulnerability Database
  • 2026-09-15 - Last updated in NVD database

Technical Details for CVE-2026-76796

Vulnerability Analysis

DYMO Connect Desktop installs a local web service to support label design and printing workflows. The LoadImageAsPngBase64 endpoint reads an image from disk, converts it to a base64-encoded PNG, and returns the payload to the caller. The endpoint accepts a client-supplied file path parameter and passes it to the underlying file read operation without validating that the target resides inside an approved directory. A local caller reaches the service over the loopback interface and requests any file whose path is known.

The fix in version 1.6.2 filters requests by file extension. Files with non-image extensions are rejected, but the service still resolves paths anywhere on the filesystem. Newell Brands documents this as accepted residual risk, so arbitrary-location reads of image files remain possible after patching.

Root Cause

The root cause is external control of a file name or path [CWE-73]. The endpoint trusts the caller-supplied path parameter, does not canonicalize the input against a root directory allowlist, and does not reject traversal sequences or absolute paths pointing outside the application's intended asset folders.

Attack Vector

Exploitation requires local access to the host running DYMO Connect Desktop. An attacker with a foothold, or a malicious page loaded in a context that can reach the local web service, issues a request to the LoadImageAsPngBase64 endpoint with a crafted path such as an absolute path to a sensitive image on disk. The service responds with the base64-encoded content, disclosing the file to the caller.

See the CVE-2026-76796 record and the Newell Rubbermaid release notes for vendor-published details.

Detection Methods for CVE-2026-76796

Indicators of Compromise

  • Loopback HTTP requests to the DYMO Connect Desktop local web service targeting the LoadImageAsPngBase64 endpoint with absolute paths or .. traversal sequences.
  • Unexpected base64-encoded PNG responses from the DYMO local service to non-DYMO client processes.
  • DYMO Connect Desktop process reading image files from user profile directories, temp folders, or other locations outside its install path.

Detection Strategies

  • Inspect loopback traffic on the DYMO local service port for requests whose filePath or equivalent parameter references paths outside the DYMO application asset directories.
  • Correlate DYMO Connect Desktop file open events with the request source process to identify browsers, scripts, or other local callers driving unusual reads.
  • Alert on DYMO Connect Desktop versions below 1.6.2 reported by endpoint inventory data.

Monitoring Recommendations

  • Enable file access auditing on directories containing sensitive image assets such as scans, screenshots, and document exports.
  • Monitor process command lines and network connections for tools issuing HTTP requests to the DYMO Connect Desktop local service listener.
  • Track software inventory for DYMO Connect Desktop installs and confirm all endpoints run version 1.6.2 or later.

How to Mitigate CVE-2026-76796

Immediate Actions Required

  • Upgrade DYMO Connect Desktop to version 1.6.2 or later on all Windows endpoints where the application is installed.
  • Inventory endpoints running DYMO Connect Desktop and prioritize systems that handle sensitive image content such as scanned documents or screenshots.
  • Review the Newell Rubbermaid release notes to confirm applied version and validate the fix.

Patch Information

Newell Brands fixed CVE-2026-76796 in DYMO Connect Desktop 1.6.2. The patch restricts the LoadImageAsPngBase64 endpoint to files matching allowed image extensions. Directory-based restriction is not enforced, so image files anywhere on disk remain readable by design. Vendor documentation is available via DYMO Support Resources and the CISA CSAF advisory.

Workarounds

  • Uninstall DYMO Connect Desktop on endpoints that do not require label design or printing functionality.
  • Restrict local host firewall rules so only the DYMO Connect Desktop client process can reach the local web service listener.
  • Store sensitive image files outside user-writable locations and apply filesystem ACLs that deny read access to the account running DYMO Connect Desktop.
bash
# Configuration example: verify installed DYMO Connect Desktop version on Windows
powershell -Command "Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Where-Object { $_.DisplayName -like 'DYMO Connect*' } | Select-Object DisplayName, DisplayVersion"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.