Signalrgb · Signalrgb · CVE-2026-8049
**Name of the Vulnerable Software and Affected Versions**
SignalRGB versions prior to 1.3.7.0
**Description**
The `.SignalIo` device object is created without an explicit SDDL (Security Descriptor Definition Language) security descriptor and without FILE DEVICE SECURE OPEN. This configuration leads to overly permissive default access control, enabling any authenticated local user to obtain a handle to the device and issue privileged IOCTLs (Input/Output Control codes), which are used to communicate directly with device drivers.
**Recommendations**
Update to version 1.3.7.0 or later.