PT-2026-106228 · Newell Brands · Dymo Id

CVE-2026-102262

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Newell Brands DYMO ID versions prior to 1.6.0
Description The software resolves its plugin Modules directory relative to the process working directory. This allows an attacker to store a job file alongside malicious modules or DLLs. When a victim opens the job file, the process working directory is set to the folder containing the file, leading to arbitrary code execution at the privilege level of the victim.
Recommendations Update to version 1.6.0.

Fix

Path traversal

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102262

Affected Products

Dymo Id