SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16247

HIGH · CVSS 7.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The LogPathConfig.exe application in versions prior to 5.06 of _connect.BRAIN on Windows improperly modifies permissions on the %ProgramData% directory, granting full control to the Everyone group instead of restricting access to specific Bizerba folders. This vulnerability poses a high risk as it could allow unauthorized users to manipulate sensitive application data. Organizations using affected versions should prioritize remediation to prevent potential data breaches and unauthorized access.

CVE
CVE-2026-16247
Severity
HIGH
CVSS
7.3
EPSS
0.10%
Windows

Original NVD Description

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool.