Description
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
Published: 2026-09-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

The vulnerability in PALLET CONTROL products arises from an incorrect default permission setting that permits a local attacker to execute arbitrary code with SYSTEM privileges. This flaw allows an attacker who has local access to the affected machine to gain full control over the system, potentially compromising all data and operations handled by the application.

Affected Systems

Vendors of concern are JAL Information Technology Co., Ltd. The impacted products include PALLET CONTROL, PalletControl, and PalletControl Cloud. No specific version information is provided, so every install of these products may be susceptible.

Risk and Exploitability

The CVSS base score of 8.5 indicates a high severity vulnerability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The primary attack vector is local; an attacker must already have physical or local network access to the device running the software to exploit this issue. Once exploited, the attacker obtains SYSTEM level rights, enabling complete takeover of the affected system.

Generated by OpenCVE AI on September 4, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest security patch or update released by JAL Information Technology for PALLET CONTROL products as soon as it becomes available.
  • Restrict local user accounts and network access that can install or run PALLET CONTROL on only trusted, hardened systems, ensuring that the application does not run with unnecessary SYSTEM privileges.
  • Continuously audit and monitor file and registry permissions associated with the application, and set up alerts for any abnormal SYSTEM‑level processes that may indicate exploitation.

Generated by OpenCVE AI on September 4, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jalinfotec
Jalinfotec pallet Control
Jalinfotec palletcontrol
Jalinfotec palletcontrol Cloud
Vendors & Products Jalinfotec
Jalinfotec pallet Control
Jalinfotec palletcontrol
Jalinfotec palletcontrol Cloud

Fri, 04 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Default Permission Vulnerability in PALLET CONTROL Enables Local Privilege Escalation to SYSTEM

Fri, 04 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Jalinfotec Pallet Control Palletcontrol Palletcontrol Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-07T05:18:12.952Z

Reserved: 2026-08-28T01:58:09.611Z

Link: CVE-2026-81302

cve-icon Vulnrichment

Updated: 2026-09-04T19:37:21.236Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T09:17:11.230

Modified: 2026-09-08T18:38:19.590

Link: CVE-2026-81302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:20:14Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions