Junglewise Threat Intelligence

CVE-2026-34527: Sandboxie-Plus entropy loss in EditPassword hashing

CVE-2026-34527 · Severity: medium · CVSS 5.3 · Published 2026-05-05

Technologies: Sandboxie-Plus, Sandboxie-Plus Sandboxie. Vendors: Sandboxie-Plus.

Executive brief

Sandboxie-Plus is a security tool used to run applications in an isolated environment to prevent them from making permanent changes to the system. A flaw in how the software stores passwords allows for much easier unauthorized access if an attacker obtains a backup or copy of the configuration file. Because of a coding error, the security of these stored passwords is significantly weaker than intended, making them vulnerable to rapid guessing attacks.

Technical details

A logic error exists in the SbieIniServer::HashPassword function within Sandboxie/core/svc/sbieiniserver.cpp. When converting a SHA-1 digest to hexadecimal, the high nibble of each byte is shifted right by 8 bits instead of 4, resulting in the high nibble always being zero. This effectively discards half of the digest information, reducing entropy to 80 bits. Combined with the use of unsalted SHA-1, this significantly lowers the computational cost for offline brute-force attacks against leaked or backed-up EditPassword hashes. The issue is resolved in version 1.17.3 by correcting the bit-shift and recommending a migration to stronger hashing schemes.

Affected products

  • Sandboxie-Plus Sandboxie-Plus <= 1.17.2

Timeline

  • 2026-05-04: advisory: GitHub advisory GHSA-w37h-qm9p-h4x2 published
  • 2026-05-05: disclosed: CVE-2026-34527 assigned
  • 2026-05-05: patched: Fixed in version 1.17.3

References

Related threats