PT-2026-51300 · Arubasign · Arubasign

·

CVE-2026-12602

·

Published

2026-06-22

·

Updated

2026-06-23

CVSS v4.0

8.8

High

VectorAV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ArubaSign versions prior to 4.6.6
Description Incorrect default permissions are assigned during the installation of the software. The main executable and other program files located in "C:Program Files" have excessive permissions for the 'Everyone' group. This allows an unprivileged user to replace the main executable or its components with a malicious file to execute arbitrary code. If the malicious code runs with elevated privileges, such as Administrator or SYSTEM, it can lead to privilege escalation and full system control.
Recommendations Update to version 4.6.6 or later.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12602

Affected Products

Arubasign