cbcvebase.
CVE-2026-9264
published 2026-05-22

CVE-2026-9264: A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through…

PriorityP350critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
0.23%
14.1th percentile
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.

Affected

1 ranges
VendorProductVersion rangeFixed in
trimblesketchup< 2026.1.32026.1.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.