AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-9169

HIGH · CVSS 8.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The LUCID Vision Labs Arena SDK on Windows is vulnerable to DLL search order hijacking, allowing local attackers to execute arbitrary code with the application's privileges by placing a malicious DLL in a user-controlled directory within the PATH environment variable. This high-severity vulnerability poses significant risks to systems utilizing the SDK, particularly in environments where untrusted users have access. Organizations using this SDK should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

CVE
CVE-2026-9169
Severity
HIGH
CVSS
8.8
EPSS
0.14%
Windows

Original NVD Description

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.