Impact
The OpenRGB network protocol permits an attacker to embed attacker‑controlled strings into arbitrary file system paths, thereby authorizing the writing of any file on the machine. This flaw is an extension of CVE‑2026‑59682 and allows a full compromise if the daemon runs with root privileges or a full account takeover if it runs under a user account. The vulnerability subverts integrity guarantees and can be leveraged to overwrite configuration files, place malicious binaries, or alter system resources, jeopardizing confidentiality, integrity, and availability. The threat description is based on the supplied national vulnerability description, and the potential for remote exploitation is inferred from the mention that the daemon may be reachable over the network. While the exact prerequisites are not enumerated, the impact remains severe: an attacker can write any file content, including executable payloads, and thus obtain code execution.
Affected Systems
The affected system is the OpenRGB application provided by CalcProgrammer1. No specific version information is available in the CNA data; the vulnerability applies to any version that implements the network protocol described in the CVE, so all released versions should be considered vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability scored a CVSS of 9.3, indicating critical severity. EPSS is not provided, so current exploitation likelihood is unknown, but the absence of KEV listing suggests no known widespread exploitation yet. The daemon may be reachable locally or over a network, meaning an attacker could exploit this flaw to create or overwrite arbitrary files. If the daemon runs with root privileges, an attacker could gain full system compromise; if it runs under a regular user, an account takeover is possible. This dual surface increases risk for both local users and administrators.
OpenCVE Enrichment