SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12663

HIGH · CVSS 7 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

ControlFLASHâ„¢ has a vulnerability where the installer improperly grants write permissions to the "Everyone" group in its installation directory. This flaw could enable arbitrary code execution, allowing attackers to execute commands with the privileges of the logged-in user. Organizations using ControlFLASHâ„¢ should prioritize addressing this issue to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12663
Severity
HIGH
CVSS
7
EPSS
0.10%

Original NVD Description

A security issue exists within ControlFLASHâ„¢, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.