Junglewise Threat Intelligence

CVE-2026-68766: hashcat command injection via restore file parsing

CVE-2026-68766 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Hashcat. Vendors: Hashcat.

Executive brief

hashcat is a widely-used password recovery tool. The vulnerability allows an attacker to craft a malicious restore file that injects command-line options, enabling arbitrary file write and potential code execution through shell startup file manipulation. An attacker can distribute a crafted restore file that, when processed by a victim, appends malicious commands to shell configuration files, leading to code execution when the user's shell starts.

Technical details

The vulnerability is a command injection flaw in hashcat's restore file parser that fails to validate or restrict command-line options when reconstructing the original command from a saved restore state. An attacker can craft a restore file containing malicious options like --outfile or --potfile-path with attacker-controlled paths and content. When hashcat parses and reconstructs the command from the restore file, it does not sanitize these options, allowing the attacker to write arbitrary content to files, including shell startup files (.bashrc, .profile, etc.), resulting in arbitrary code execution. The attack requires the victim to process a malicious restore file, but requires no authentication or special privileges from hashcat itself.

Affected products

  • hashcat hashcat prior to patch for CVE-2026-68766

Timeline

  • 2026-08-22: disclosed
  • 2026-08-22: advisory: CVE-2026-68766 published

References

Related threats