Exploitation Summary
EIP tracks 12 public exploits for CVE-2026-0776. PoCs published by whenx, whoanx, AnhedonicX.
AI-analyzed exploit summary This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
Description
Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the discord_rpc module. The product loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-27057.
Exploits (12)
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup, executing arbitrary JavaScript within the Discord process context.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup, executing arbitrary JavaScript within the Discord process context.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits an uncontrolled search path element (CWE-427) in Discord Desktop Client for Windows by placing a malicious Node.js module in a predictable location (C:\node_modules). When Discord launches, it loads the module, executing arbitrary JavaScript code with the privileges of the current user.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates how an attacker can achieve local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup.
This PoC exploits CVE-2026-0776, an uncontrolled search path element vulnerability in Discord Desktop Client (v1.0.9196) on Windows. It demonstrates local code execution by placing a malicious Node.js module in a predictable location (C:\node_modules) that Discord loads during startup, executing arbitrary JavaScript within the Discord process context.
This repository contains a functional PoC for CVE-2026-0776, demonstrating an uncontrolled search path element vulnerability in Discord's Node.js module resolution. The exploit deploys a malicious 'utf-8-validate.js' module to a predictable path, which Discord loads and executes when launched.
The repository contains a README with a vague description of CVE-2026-0776, claiming it exploits a Discord feature to open a command prompt as admin. No technical details, exploit code, or proof-of-concept implementation are provided.
References (1)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H