SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59683

CRITICAL · CVSS 9.8 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The OpenRGB network protocol is vulnerable to arbitrary file system path manipulation, enabling attackers to write controlled strings that can lead to full system compromise or account takeover, depending on the daemon's execution context. Organizations using OpenRGB, especially those with the daemon running as root, should prioritize immediate remediation due to the critical severity of this vulnerability. This poses a significant risk to both local and remote systems, necessitating urgent attention from cybersecurity teams.

CVE
CVE-2026-59683
Severity
CRITICAL
CVSS
9.8
EPSS
0.58%

Original NVD Description

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context).