Description
A local privilege escalation vulnerability in ESET Inspect Connector. 
The vulnerability was caused by improper authentication in an IPC channel.
Published: 2026-07-16
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ESET Inspect Connector contains a flaw where an ALPC channel does not perform proper authentication. The vendor description does not expand the acronym ALPC; it is understood to refer to a Windows inter-process communication channel, an inference not stated explicitly. This weakness enables a local attacker to impersonate a privileged process and execute actions with elevated rights. The vulnerability aligns with CWE‑269, which describes authentication bypass through privilege escalation, and can allow attackers to gain system‑level access on the affected host.

Affected Systems

The issue affects the ESET Inspect Connector component provided by ESET, spol. s.r.o. No specific version ranges are listed in the entry, so any installation of this product that has not been updated according to the vendor advisory is potentially vulnerable.

Risk and Exploitability

The CVSS base score is 8.5, indicating a high severity for local privilege escalation. However, the EPSS score is less than 1%, so the likelihood of exploitation in the wild is currently very low. The vulnerability is not listed in the to the affected machine and relies on the ability to interact with the ALPC IPC channel, making remote exploitation unlikely without prior local compromise.

Generated by OpenCVE AI on July 31, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ESET Inspect Connector to the latest version released by ESET, following the vendor’s advisory for CVE-2026-6423.
  • Restart the Inspect Connector service after applying the patch to ensure the updated binaries are loaded.
  • Verify that the ALPC the service’s authentication settings; if the configuration cannot be changed, place the Inspect Connector in a restricted user context with no elevated privileges.

Generated by OpenCVE AI on July 31, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Eset
Eset inspect Connector
Vendors & Products Eset
Eset inspect Connector

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.
Title Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Eset Inspect Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2026-07-16T12:34:49.159Z

Reserved: 2026-04-16T08:03:11.185Z

Link: CVE-2026-6423

cve-icon Vulnrichment

Updated: 2026-07-16T12:34:40.330Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management