CVE-2026-41527: Kde Kleopatra

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.

Affected products

  • Kde Kleopatra: before 26.08.0 (fixed in 26.08.0)

Published 2026-04-21. Last modified 2026-06-17.