Junglewise Threat Intelligence

CVE-2026-33430: BeeWare Briefcase privilege escalation in Windows MSI installers

CVE-2026-33430 · Severity: high · CVSS 7.3 · Published 2026-03-23

Vendors: PyPI.

Executive brief

Briefcase is a tool used by developers to package Python projects into standalone applications. A vulnerability in the way it creates Windows installers (MSI files) can lead to insecure folder permissions on a user's computer. This allows a standard user to replace the application's files with malicious ones; if an administrator later runs the application, the attacker's code will execute with full administrative privileges.

Technical details

A vulnerability exists in the WXS templates used by Briefcase to generate Windows MSI installers. When an application is installed in a per-machine scope ('All Users'), the installation directory may inherit insecure permissions from its parent directory (CWE-732). A local, authenticated user with low privileges can exploit this to modify or replace application binaries. If a user with higher privileges (such as an administrator) subsequently executes the tampered binary, the attacker's code runs with elevated privileges. The issue was addressed by updating the 'briefcase-windows-app-template' and 'briefcase-windows-VisualStudio-template' to explicitly define secure directory permissions.

Affected products

  • BeeWare briefcase >= 0.3.0, < 0.3.26

Timeline

  • 2026-03-20: disclosed
  • 2026-03-23: advisory: GitHub Advisory published
  • 2026-03-26: other: NVD published

References