CVE-2026-1880
Last modified
CVE-2026-1880 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ASUS | DriverHub | before 1.0.6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-1880?
How severe is CVE-2026-1880?
How do I fix CVE-2026-1880?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18789The Ezoic WordPress plugin before 2.23.1 does not properly r…7.5
- CVE-2026-1879A vulnerability was detected in Harvard University IQSS Data…6.3
- CVE-2026-18790A weakness has been identified in Systerel S2OPC up to 1.7.3…3.3
- CVE-2026-18794The OpenRGB network protocol allows attackers to cause memor…8.2
- CVE-2026-18796Any application that uses external QSPI flash for encry…6.8
- CVE-2026-18798Issue summary: QUIC server may double free QRX (QUIC record …7.5
- CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection …9.3
- CVE-2026-18806External control of file name or path vulnerability in TÜBİT…7.1
- CVE-2026-18807The ECS WordPress plugin before 4.3.8 does not have capabil…4.3
- CVE-2026-18808Improper Control of Generation of Code ('Code Injection') vu…9.8
- CVE-2026-18809Information disclosure in Firefox for Android and Firefox Fo…6.5
- CVE-2026-1881The Broadstreet plugin for WordPress is vulnerable to Insecu…4.3
Are you affected by CVE-2026-1880?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
