Skip to content
High-Severity Telegram Desktop Vulnerability Allows Account Takeover

High-Severity Telegram Desktop Vulnerability Allows Account Takeover

First seen 9 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 17:38 UTC
  • •CVE-2026-107181 affects Telegram Desktop versions 7.2.8 and earlier.
  • •Attackers can exploit the flaw to steal session files via crafted links.
  • •A patch was released on September 17, 2026, to mitigate the risk.

A high-severity vulnerability, tracked as CVE-2026-107181, was discovered in Telegram Desktop versions 7.2.8 and earlier, allowing potential account takeover under specific conditions. The flaw enables attackers to steal session files by tricking users into clicking a crafted external link that executes command injection. Users without a local password are particularly at risk. Telegram released a patch in version 7.2.9 on September 17, 2026, to address this vulnerability. A proof of concept for the exploit was made public on October 7, 2026, raising concerns about its potential exploitation in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
Telegram releases patch
Telegram fixed the vulnerability in Desktop version 7.2.9, addressing the account takeover risk.
Tokenpost
2026-10-07
PoC for Telegram flaw released
Researcher Beaksec published a public proof of concept for CVE-2026-107181, demonstrating the exploit's capabilities.
Cybersecuritynews
2026-10-07
CVE-2026-107181 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-09
Vulnerability disclosed
Tokenpost reported on the high-severity vulnerability in Telegram Desktop, detailing the risks and affected versions.
Tokenpost

More articles in this cluster (2)

Following this threat?

Track CVE-2026-107181 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Telegram Desktop are affected?
Telegram Desktop versions 7.2.8 and earlier are affected by CVE-2026-107181.
What should users do to protect themselves?
Users should update to Telegram Desktop version 7.2.9 or later to mitigate the vulnerability.
Is there evidence of active exploitation?
As of now, there is no confirmed evidence of active exploitation in the wild, but a proof of concept has been released.