CVE-2026-76796 | Newell Brands DYMO Connect Desktop up to 1.6.1 Local Web Service LoadImageAsPngBase64 file_path path traversal (EUVD-2026-79626)
A vulnerability classified as problematic has been found in Newell Brands DYMO Connect Desktop up to 1.6.1. Impacted is the function LoadImageAsPngBase64 of the component Local Web Service. This manipulation of the argument file_path causes path traversal.
This vulnerability appears as CVE-2026-76796. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.