Description
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
Published: 2026-09-04
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in PALLET CONTROL products arises from an incorrect default permission setting that permits a local attacker to execute arbitrary code with SYSTEM privileges. This flaw allows an attacker who has local access to the affected machine to gain full control over the system, potentially compromising all data and operations handled by the application.

Affected Systems

Vendors of concern are JAL Information Technology Co., Ltd. The impacted products include PALLET CONTROL, PalletControl, and PalletControl Cloud. No specific version information is provided, so every install of these products may be susceptible.

Risk and Exploitability

The CVSS base score of 8.5 indicates a high severity vulnerability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The primary attack vector is local; an attacker must already have physical or local network access to the device running the software to exploit this issue. Once exploited, the attacker obtains SYSTEM level rights, enabling complete takeover of the affected system.

Generated by OpenCVE AI on September 4, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest security patch or update released by JAL Information Technology for PALLET CONTROL products as soon as it becomes available.
  • Restrict local user accounts and network access that can install or run PALLET CONTROL on only trusted, hardened systems, ensuring that the application does not run with unnecessary SYSTEM privileges.
  • Continuously audit and monitor file and registry permissions associated with the application, and set up alerts for any abnormal SYSTEM‑level processes that may indicate exploitation.

Generated by OpenCVE AI on September 4, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Default Permission Vulnerability in PALLET CONTROL Enables Local Privilege Escalation to SYSTEM

Fri, 04 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-04T09:04:08.947Z

Reserved: 2026-08-28T01:58:09.611Z

Link: CVE-2026-81302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T09:17:11.230

Modified: 2026-09-04T09:17:11.230

Link: CVE-2026-81302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T10:30:17Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions