CVE-2026-32680
Last modified
CVE-2026-32680 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to execute an arbitrary code with SYSTEM privilege.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-32680?
How severe is CVE-2026-32680?
How do I fix CVE-2026-32680?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32669Code injection vulnerability exists in BUFFALO Wi-Fi router …9.8
- CVE-2026-32673A vulnerability exists in BIG-IP scripted monitors that may …8.7
- CVE-2026-32677Path traversal for some gaudi-container-runtime before versi…5.4
- CVE-2026-32678Authentication bypass issue exists in BUFFALO Wi-Fi router p…8.7
- CVE-2026-32679The installers of LiveOn Meet Client for Windows (Downloader…8.4
- CVE-2026-3268A vulnerability was detected in psi-probe PSI Probe up to 5.…4.3
- CVE-2026-32682When NGINX Gateway Fabric is configured using GRPCRoutes, an…7.1
- CVE-2026-32683Some EZVIZ products utilize older versions of cloud feature …5.3
- CVE-2026-32684The application does not impose strict enough restrictions o…2.9
- CVE-2026-32685Path traversal vulnerability in Gleam's handling of custom d…4.6
- CVE-2026-32686Uncontrolled Resource Consumption vulnerability in ericmj de…6.9
- CVE-2026-32687Improper Neutralization of Special Elements used in an SQL C…7.8
Are you affected by CVE-2026-32680?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
