PT-2026-84212 · Unknown · Controlflash

CVE-2026-12663

·

Published

2026-09-01

·

Updated

2026-09-04

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ControlFLASH versions 15.07 and earlier
Description The installer grants write permissions to the Everyone group on the product installation directory. This flaw allows for arbitrary code execution, enabling an attacker to run any commands or code of their choice on a target machine at the permission level of the logged-in user.
Recommendations Update to version 15.08.

Fix

LPE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12663

Affected Products

Controlflash