CVE-2026-7280

AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.
Configurations

No configuration.

History

28 Apr 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 10:16

Updated : 2026-04-28 20:22


NVD link : CVE-2026-7280

Mitre link : CVE-2026-7280

CVE.ORG link : CVE-2026-7280


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element