CVE-2026-12663

A security issue exists within ControlFLASHâ„¢, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 14:17

Updated : 2026-09-01 20:50


NVD link : CVE-2026-12663

Mitre link : CVE-2026-12663

CVE.ORG link : CVE-2026-12663


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function