CVE-2026-30332 is a Time-of-Check to Time-of-Use (TOCTOU) race condition in Balena Etcher for Windows prior to version 2.1.4. During the image flashing process, Etcher uses a legitimate script in a privileged workflow, but the application does not adequately protect the checked resource from modification before use. An attacker can win the race by replacing the legitimate script with a crafted payload after validation but before execution, causing the malicious payload to run in the privileged context used by the flashing operation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, single-purpose local privilege escalation proof-of-concept for CVE-2026-30332 affecting Balena Etcher on Windows. It contains two files: a README describing the vulnerability and exploitation steps, and exploit.py implementing the attack. The Python script continuously monitors the current user's Etcher temp directory for files matching balena-etcher-electron-*.cmd. When such a file appears, it overwrites the file contents with a crafted batch payload. The payload preserves expected Etcher environment variables, adds malicious commands to create a new local user and place it in the Administrators group, and finally launches etcher-util.exe from the Balena Etcher installation path. The exploit does not use any remote network communication; it is a local race-condition/TOCTOU attack that depends on Etcher creating a writable temporary script and later executing it with elevated privileges after UAC approval. The code is straightforward and operational rather than framework-based, with a hardcoded payload and target paths.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.