CVE-2026-5397
Last modified
CVE-2026-5397 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OMRON SOCIAL SOLUTIONS CO., Ltd. | PowerAttendant Standard Edition | 2.1.2 or lower |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5397?
How severe is CVE-2026-5397?
How do I fix CVE-2026-5397?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53962Discourse is an open-source discussion platform. Prior to 20…5.4
- CVE-2026-53963Discourse is an open-source discussion platform. Prior to 20…9
- CVE-2026-53965The MCP PHP SDK (Composer package mcp/sdk) is the official M…6.9
- CVE-2026-53966XWiki Platform is a generic wiki platform. From 13.4-rc-1 un…7.1
- CVE-2026-53968Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-53969Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-53970ZeroBrew version 0.3.1 and prior contains a missing integrit…7.5
- CVE-2026-53974Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-53975OpenChamber 1.11.7 contains an unauthenticated remote code e…9.8
- CVE-2026-53976OpenChamber 1.11.7 contains a path traversal vulnerability i…9.1
- CVE-2026-53977OpenChamber 1.11.7 contains an authentication bypass vulnera…7.5
- CVE-2026-53978Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-5397?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
