CVE-2024-3507: Lunar

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to perform a secondary process injection into the Lunar application and abuse those rights to access sensitive user information.

Affected products

  • Lunar Lunar: from 6.0.2, before 6.6.0 (fixed in 6.6.0)

Published 2024-05-08. Last modified 2026-06-17.