A vulnerability identified as problematic has been detected in notepad-plus-plus Notepad++ up to 8.9.6. Impacted is an unknown function of the file shortcuts.xml of the component Macro. Performing a manipulation of the argument settingsDir results in improper privilege management.

This vulnerability is reported as CVE-2026-71858. The attack requires a local approach. No exploit exists.

You should upgrade the affected component.