OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102262

HIGH · CVSS 7.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to execute arbitrary code at the victim's privilege level by placing malicious modules alongside a job file, which is executed when the victim interacts with it. This issue affects users of Newell Brands DYMO ID version 1.5.1.71 and should be prioritized by organizations using this software to mitigate potential exploitation risks. Users are strongly advised to upgrade to version 1.6.0, where the vulnerability has been addressed.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102262
Severity
HIGH
CVSS
7.3
EPSS
0.21%

Original NVD Description

Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.