Missing authentication for critical function vulnerability exists in VOCALOID6. (CVE-2026-76137)
A missing authentication vulnerability in VOCALOID6 allows processes running under the same local user account as the VOCALOID6 Editor to escalate privileges via a local named pipe. This issue does not require user interaction and has a moderate impact on confidentiality without affecting integrity or availability.
AI Analysis
Technical Summary
CVE-2026-76137 describes a missing authentication vulnerability (CWE-306) in VOCALOID6. Specifically, any process running under the same local user account as a VOCALOID6 Editor instance can escalate privileges by exploiting a local named pipe due to lack of proper authentication checks. The vulnerability has a CVSS 3.1 base score of 3.3, indicating low complexity and requiring local access with low privileges. There is no indication of integrity or availability impact.
Potential Impact
The vulnerability allows local privilege escalation within the same user context, potentially exposing confidential information accessible to the VOCALOID6 Editor process. There is no impact on system integrity or availability. Exploitation requires local access and no user interaction is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access and avoid running untrusted processes under the same user account as VOCALOID6 Editor.
Missing authentication for critical function vulnerability exists in VOCALOID6. (CVE-2026-76137)
Description
A missing authentication vulnerability in VOCALOID6 allows processes running under the same local user account as the VOCALOID6 Editor to escalate privileges via a local named pipe. This issue does not require user interaction and has a moderate impact on confidentiality without affecting integrity or availability.
CVSS v3.1
Score 3.3low
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76137 describes a missing authentication vulnerability (CWE-306) in VOCALOID6. Specifically, any process running under the same local user account as a VOCALOID6 Editor instance can escalate privileges by exploiting a local named pipe due to lack of proper authentication checks. The vulnerability has a CVSS 3.1 base score of 3.3, indicating low complexity and requiring local access with low privileges. There is no indication of integrity or availability impact.
Potential Impact
The vulnerability allows local privilege escalation within the same user context, potentially exposing confidential information accessible to the VOCALOID6 Editor process. There is no impact on system integrity or availability. Exploitation requires local access and no user interaction is needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access and avoid running untrusted processes under the same user account as VOCALOID6 Editor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-67jp-qgv9-229c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76137"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a885f36acd9273b493f84fe
Added to database: 08/21/2026, 14:22:46 UTC
Last enriched: 08/21/2026, 14:45:19 UTC
Last updated: 08/21/2026, 14:52:00 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.