Junglewise Threat Intelligence

CVE-2026-76137: Yamaha VOCALOID6 missing authentication for named pipe

CVE-2026-76137 · Severity: low · CVSS 3.3 · Published 2026-08-21

Executive brief

VOCALOID6 is Yamaha's audio synthesis software used by musicians and content creators to generate vocal performances. A flaw in the application allows any program running under the same local user account to escalate privileges by communicating with VOCALOID6 through an unprotected local named pipe, potentially granting unauthorized access to system resources.

Technical details

This vulnerability (CVE-2026-76137) is a missing authentication flaw (CWE-306) in VOCALOID6 Editor versions 6.13.1 and earlier. The application exposes a local named pipe without proper authentication controls, allowing any process running under the same local user account to interact with it. An attacker can exploit this via the named pipe to escalate privileges or perform unauthorized operations. This requires local access and the VOCALOID6 Editor to be running; privilege escalation is possible without requiring elevated privileges initially. Yamaha released version 6.13.3 (September 16, 2026) to address this issue.

Affected products

  • Yamaha VOCALOID6 Editor 6.13.1 and earlier

Timeline

  • 2026-08-21: disclosed: Vulnerability disclosed by JPCERT/CC and NVD
  • 2026-09-16: patched: VOCALOID6 Editor version 6.13.3 released

References

Related threats