CVE-2026-9492
Last modified
CVE-2026-9492 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and writing physical memory and obtaining kernel-level privileges.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and writing physical memory and obtaining kernel-level privileges.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| GIGABYTE | MBStorage | <= 26.02.10.01 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-9492?
How severe is CVE-2026-9492?
How do I fix CVE-2026-9492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9484A vulnerability was determined in SourceCodester Student Gra…6.3
- CVE-2026-9485A vulnerability was identified in SourceCodester Student Gra…3.5
- CVE-2026-9486A security flaw has been discovered in SourceCodester Studen…4.3
- CVE-2026-9487XML::Sig versions before 0.71 for Perl allow signature wrapp…9.1
- CVE-2026-9489NitroSense 3.x before 3.01.3052 contains Local Privilege Esc…8.5
- CVE-2026-9490A security vulnerability has been identified in Acer Care Ce…5.5
- CVE-2026-9493Service Center developed by BankPro E-Service Technology has…7.1
- CVE-2026-9494An information disclosure vulnerability exists in Canonical …5.5
- CVE-2026-9495Versions of the package @koa/router from 14.0.0 and before 1…7.3
- CVE-2026-9496Versions of the package pacote from 11.2.7 and before 21.5.1…7.7
- CVE-2026-9497A flaw has been found in changmingxie tcc-transaction up to …6.3
- CVE-2026-9498A vulnerability has been found in Dromara lamp-cloud up to 5…6.3
Are you affected by CVE-2026-9492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
