← Terug naar overzicht

CVE-2026-59682 describes an arbitrary file overwrite vulnerability in OpenRGB affecting versions through 1.0rc3. The vulnerability is triggered via a SAVE_PROFILE message, potentially allowing an attacker to overwrite arbitrary files on the system. This could lead to privilege escalation, data destruction, or code execution depending on which files are overwritten. The issue has been reported via SUSE Bugzilla and a fix has been committed to the OpenRGB GitLab repository. The patch is referenced in commit d2dd9dcc7369e78f47d01ace19af3750cd89ae66. Users of OpenRGB up to and including version 1.0rc3 are advised to apply the fix or update to a patched version. The vulnerability has been assigned a high criticality rating.

Affected products

  • OpenRGB 1.0rc3

Related CVE's

  • CVE-2026-59682

Categories

  • Operating Systems
  • Security Tools