SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-8920

HIGH · CVSS 8.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Aura Wallpaper Service is vulnerable to improper restrictions that allow local users to execute file operations by sending crafted commands with arbitrary file paths, bypassing intended path restrictions. This could potentially lead to unauthorized access to files or the unavailability of certain features on specific models. Users and administrators of affected ASUS devices should prioritize applying the security update to mitigate these risks.

CVE
CVE-2026-8920
Severity
HIGH
CVSS
8.5
EPSS
0.10%

Original NVD Description

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.