An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

Project Subscriptions

Vendors Products
Expressupdate Agent For Windows Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 26 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nec
Nec expressupdate Agent For Windows
Vendors & Products Nec
Nec expressupdate Agent For Windows

Fri, 26 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Title Access Control Deficiency in ExpressUpdate Agent Enables SYSTEM-Privilege Code Execution

Fri, 26 Jun 2026 05:00:00 +0000

Type Values Removed Values Added
Description An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
Weaknesses CWE-782
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2026-06-26T12:19:51.182Z

Reserved: 2026-05-18T01:11:09.851Z

Link: CVE-2026-8797

cve-icon Vulnrichment

Updated: 2026-06-26T12:19:46.415Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T09:35:51Z

Weaknesses