CVE-2026-1286

Unspecified Product - Deserialization

Title source: llm

Description

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.

Scores

EPSS 0.0022
EPSS Percentile 44.5%

Classification

CWE
CWE-502
Status draft

Timeline

Published Mar 10, 2026
Tracked Since Mar 11, 2026