Junglewise Threat Intelligence

CVE-2026-71858: Notepad++ shortcuts.xml macro HMAC validation bypass

CVE-2026-71858 · Severity: info · Published 2026-08-17

Technologies: Notepad++. Vendors: Notepad++.

Executive brief

Notepad++ is a popular source code editor that allows users to define custom keyboard shortcuts and macros. Prior to version 8.9.7, attackers could bypass security validation on macros loaded from a shortcuts.xml file, potentially allowing execution of elevated commands or modification of protected files if they can influence where the application loads its configuration. This affects users who open files or projects from untrusted sources.

Technical details

The vulnerability is a cryptographic validation bypass affecting the macro system in Notepad++. Macros loaded from an attacker-controlled shortcuts.xml file bypass HMAC validation that is normally applied to UserDefinedCommands. When this validation is bypassed, an attacker can invoke Scintilla actions and the internal "Open in Default Viewer" command in an elevated Notepad++ process. The attack requires a local attacker to influence the settingsDir configuration parameter and a user to trigger the malicious macro. The vulnerability is fixed in version 8.9.7, which properly validates HMAC signatures before executing macros.

Affected products

  • Notepad++ Notepad++ prior to 8.9.7

Timeline

  • 2026-08-17: disclosed
  • 2026-07-14: patched: Fix released in version 8.9.7

References