{"id":"CVE-2026-41527","details":"KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.","modified":"2026-08-22T03:53:04.987304624Z","published":"2026-04-21T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41527.json","cna_assigner":"mitre","cwe_ids":["CWE-670"]},"references":[{"type":"WEB","url":"https://commits.kde.org/kleopatra/73471abb92d99c56354adb582bfaec2764c22b79"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41527.json"},{"type":"ADVISORY","url":"https://kde.org/info/security/advisory-20260408-1.txt"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41527"},{"type":"PACKAGE","url":"https://github.com/KDE/kleopatra/releases"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kde/kleopatra","events":[{"introduced":"0"},{"fixed":"2ddbfd59b145ac527383fb7910b9f1f00d2fdcf4"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"26.08.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v26.07.90","v26.07.80","gpg4win-5.0.0-beta479","gpg4win-5.0.0-beta395","gpg4win-5.0.0-beta369","v24.01.90","v24.01.85","v24.01.80","v24.01.75","gpg4win-3.1.26","gpg4win-3.1.24","v20.07.80","v20.03.80","v19.07.80","v19.03.80","v18.11.80","v18.07.80","v18.03.80","v17.07.80","v17.03.80","v16.11.80","v16.07.90","v16.07.80","v16.03.90","v16.03.80"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41527.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}