Is DLP vulnerable to CVE-2026-8926
search cancel

Is DLP vulnerable to CVE-2026-8926

book

Article ID: 450673

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like https://[email protected]/, curl could wrongly get and use the password for another user set in the .netrc file for that host if such a one exists and there is no match for the specified user.

Resolution

DLP does not use .netrc for credentials. CURLOPT_NETRC is never set. Symantec DLP authenticates via client certificate (mTLS via SSL_CTX_use_certificate()), not username/password.