Description
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.

This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
Published: 2026-07-28
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a classic Search Order Hijacking (CWE‑427) in ArkSigner Desktop Client. An attacker able to place a malicious executable in a directory that appears earlier in the client’s search path can cause the client to load and run that code instead of the intended binary. This can lead to arbitrary code execution and privilege escalation on the infected system.

Affected Systems

Affected is ArkSigner Desktop Client from version 2.2.16.10 through 17062026, distributed by ArkSigner Software and Hardware Industry and Trade Inc. No other vendors or products are listed.

Risk and Exploitability

With a CVSS score of 7.3 the vulnerability is considered high severity. The EPSS score is below 1%, indicating a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. Based on the description, the likely attack vector is an attacker placing a malicious binary in an earlier directory of the client’s search path and gaining influence over that path, which is typically a local or privileged action. In an environment where ArkSigner runs with elevated rights, successful exploitation could allow an attacker to execute arbitrary code with the same privileges as the client.

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ArkSigner Desktop Client to the latest patched release if available
  • Reconfigure the client’s search path to exclude writable or untrusted directories
  • Run the client with the least privilege necessary and monitor the search path for unauthorized executables

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Arksigner
Arksigner arksigner Desktop Client
Vendors & Products Arksigner
Arksigner arksigner Desktop Client

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
Title Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Arksigner Arksigner Desktop Client
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-28T14:45:32.059Z

Reserved: 2026-05-08T11:29:48.099Z

Link: CVE-2026-8164

cve-icon Vulnrichment

Updated: 2026-07-28T14:45:24.991Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T15:17:51.633

Modified: 2026-07-28T16:20:22.133

Link: CVE-2026-8164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element