Description
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.
Published: 2026-08-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in StableBit Scanner 2.6.13.4088, specifically affecting the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe. The misconfigured file permissions allow a local attacker to manipulate the executable’s access rights, potentially enabling the attacker to execute arbitrary code or elevate privileges on the host. This flaw is exploited through local execution alone, and a publicly available exploit has been documented, indicating that the attack may be widely accessible to those with local access.

Affected Systems

The affected vendor and product are StableBit Scanner, version 2.6.13.4088. The vulnerability impacts the ScannerService component of the application, which runs under default system privileges on Windows installations of the scanner.

Risk and Exploitability

With a CVSS score of 8.5, the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity may be limited. However, because the attack vector is local, any user with physical or remote console rights could potentially exploit the mis‑configured permissions. The risk is therefore elevated for systems where the StableBit Scanner service is configured to run with administrative rights or where file permissions are overly permissive for non‑privileged users.

Generated by OpenCVE AI on August 7, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade StableBit Scanner to a patched version that corrects the Scanner.Service.exe permission handling.
  • If an upgrade cannot be performed immediately, adjust the file system permissions on C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe to deny write access to non‑administrator accounts and verify the file integrity using a known hash.
  • Re‑configure the StableBit Scanner service to run under a least‑privilege system account and enable auditing of the service’s launch events to detect unauthorized modifications or privilege escalation attempts.

Generated by OpenCVE AI on August 7, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.
Title StableBit Scanner ScannerService Scanner.Service.exe permission
First Time appeared Stablebit
Stablebit scanner
Weaknesses CWE-266
CWE-275
CPEs cpe:2.3:a:stablebit:scanner:*:*:*:*:*:*:*:*
Vendors & Products Stablebit
Stablebit scanner
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Stablebit Scanner
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T02:30:09.530Z

Reserved: 2026-08-06T19:59:50.226Z

Link: CVE-2026-19190

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T04:30:07Z

Weaknesses