CVE-2020-36928

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:brother:bragent:1.38:*:*:*:*:*:*:*

History

09 Feb 2026, 15:04

Type Values Removed Values Added
First Time Brother bragent
Brother
CPE cpe:2.3:a:brother:bragent:1.38:*:*:*:*:*:*:*
References () https://help.brother-usa.com/app/answers/detail/a_id/174732/~/what-is-bragent%3F - () https://help.brother-usa.com/app/answers/detail/a_id/174732/~/what-is-bragent%3F - Product
References () https://www.exploit-db.com/exploits/50010 - () https://www.exploit-db.com/exploits/50010 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/brother-bragent-wbaagentclient-unquoted-service-path - () https://www.vulncheck.com/advisories/brother-bragent-wbaagentclient-unquoted-service-path - Third Party Advisory

16 Jan 2026, 17:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50010 - () https://www.exploit-db.com/exploits/50010 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-02-09 15:04


NVD link : CVE-2020-36928

Mitre link : CVE-2020-36928

CVE.ORG link : CVE-2020-36928


JSON object : View

Products Affected

brother

  • bragent
CWE
CWE-428

Unquoted Search Path or Element