CVE-2026-8920

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
CVSS

No CVSS.

References
Configurations

No configuration.

History

15 Jul 2026, 02:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 02:22

Updated : 2026-07-15 16:24


NVD link : CVE-2026-8920

Mitre link : CVE-2026-8920

CVE.ORG link : CVE-2026-8920


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints