Description
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.
Published: 2026-08-07
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a local attacker to manipulate permissions in the DrivePoolService component of StableBit DrivePool 2.3.13.1687, potentially granting elevated privileges. This misconfiguration can let an attacker bypass intended access controls and gain higher system permissions on the host.

Affected Systems

Affected systems are installations of StableBit DrivePool version 2.3.13.1687 running on Windows, specifically the DrivePoolService component located in C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity local privilege escalation risk, while the EPSS score is not available, making the exact exploitation probability uncertain. The vulnerability is not in the CISA KEV catalog. Because the attack vector is local, only users with local system access can exploit it, and after successful execution, the attacker can elevate privileges, potentially compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 7, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update StableBit DrivePool to the latest available release to patch the permission manipulation flaw.
  • Restrict local user rights to the DrivePool.Service.exe file and related configuration directories to prevent unauthorized manipulation.
  • Monitor for anomalous interactions with DrivePoolService and enforce strict access controls on its service files and registry settings.

Generated by OpenCVE AI on August 7, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.
Title StableBit DrivePool DrivePoolService DrivePool.Service.exe permission
First Time appeared Stablebit
Stablebit drivepool
Weaknesses CWE-266
CWE-275
CPEs cpe:2.3:a:stablebit:drivepool:*:*:*:*:*:*:*:*
Vendors & Products Stablebit
Stablebit drivepool
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Stablebit Drivepool
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T17:36:19.148Z

Reserved: 2026-08-06T20:00:01.802Z

Link: CVE-2026-19191

cve-icon Vulnrichment

Updated: 2026-08-07T17:36:03.027Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T05:17:01.313

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:58:30Z

Weaknesses