OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-7169

HIGH · CVSS 7.5 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Evope Collector versions prior to 1.1.7.13 are vulnerable due to an unchecked search path element that permits local attackers to load a malicious DLL by placing it in the 'C:\ProgramData\Evope\' directory. This flaw allows the 'Evope.Service.exe' component, running with SYSTEM privileges, to execute arbitrary code, leading to local privilege escalation. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-7169
Severity
HIGH
CVSS
7.5
EPSS
0.14%

Original NVD Description

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation.