Description
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Published: 2026-10-05
Score: 7 High
EPSS: n/a
KEV: No
Impact: Local Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the way DYMO ID resolves the location of its plugin modules relative to the current working directory. By delivering a specially crafted job file alongside a malicious module or DLL, an attacker can trick the application into treating the job folder as its working directory. When the victim opens the file, the application loads the malicious DLL and executes it with the same privileges that the user process runs under, giving the attacker the ability to run arbitrary code on the system.

Affected Systems

This weakness has been documented for DYMO ID version 1.5.1.71 and is fixed in version 1.6.0. No other affected product versions are listed in the CNA data. The product is sold by Newell Brands.

Risk and Exploitability

The CVSS score of 7 indicates a moderate severity, and the lack of a published EPSS score means there is no publicly available evidence of exploitation, though the flaw is not listed in the CISA KEV catalog. Attackers would need local access to place the malicious job file and rely on a user opening the file, which makes the vulnerability a local privilege escalation that can lead to full code execution on the victim’s machine.

Generated by OpenCVE AI on October 5, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to DYMO ID v1.6.0, which contains the vendor‑supplied fix for the path resolution issue.
  • Restrict the creation and execution of job files to trusted directories and remove any unrestricted write access for non‑administrative users.
  • Monitor system logs for unusual DLL load events or unexpected process activity that may indicate exploitation of the module loading mechanism.

Generated by OpenCVE AI on October 5, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Title Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control
Weaknesses CWE-22
CWE-668
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-05T20:37:26.019Z

Reserved: 2026-09-28T20:09:51.956Z

Link: CVE-2026-102262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:32.400

Modified: 2026-10-05T21:16:32.400

Link: CVE-2026-102262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-668

    Exposure of Resource to Wrong Sphere