CVE-2026-9169

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 09:16

Updated : 2026-08-26 16:39


NVD link : CVE-2026-9169

Mitre link : CVE-2026-9169

CVE.ORG link : CVE-2026-9169


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element