← Terug naar overzicht

CVE-2026-59683 describes a critical vulnerability in the OpenRGB network protocol that allows attackers to write attacker-controlled strings to arbitrary file system paths. This is an extension of CVE-2026-59682 and can lead to full system compromise if the OpenRGB daemon is running as root, or full account takeover if running in user context. The vulnerability can be exploited both locally and remotely. A fix has been committed to the OpenRGB GitLab repository. The issue has also been tracked via SUSE Bugzilla. The severity is considered high due to the potential for complete system or account compromise without requiring complex prerequisites.

Affected products

  • OpenRGB

Related CVE's

  • CVE-2026-59682
  • CVE-2026-59683

Categories

  • Network Infrastructure
  • Operating Systems
  • Zero-Day Vulnerabilities