SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90891

MEDIUM · CVSS 5.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The ASRock Polychrome SYNC/RGB software utility for Chrome is vulnerable to improper access control, allowing authenticated local attackers to exploit the driver by sending specially crafted IOCTL requests. This can lead to unauthorized access to restricted I/O ports, potentially causing a forced reboot of the operating system. Organizations using ASRock products should prioritize addressing this vulnerability to mitigate the risk of local attacks.

CVE
CVE-2026-90891
Severity
MEDIUM
CVSS
5.5
EPSS
N/A
Chrome

Original NVD Description

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.