By weakness (CWE)

CWE-296: related vulnerabilities

CVEs classified under CWE-296. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2026-24066HIGH 8.4

    Slate Digital Connect version 1.37.0 for macOS contains a critical flaw in how it validates connections to a privileged system service. The application installs a helper tool that runs with elevated privileges, but when other programs attempt to connect to it, the helper only checks one field of the requesting program's digital certificate—specifically, the organizational unit—without verifying that the certificate actually comes from a trusted authority. An attacker on the same Mac can create a fake certificate with the correct organizational unit value and trick the helper into granting them privileged access, potentially allowing them to escalate their permissions to admin-level capabilities.