CVE-2026-81302CWE-276

CVE-2026-81302

High · published September 4, 2026

CVSS v3.0
7.8
EPSS
0%
Percentile
4.8
In the wild
Unconfirmed
What it is

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

The record
Technical detail
CVSS v3.0
7.8 · HIGH
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.5 · CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00153 · 4.8th percentile
Weakness
CWE-276 · Incorrect Default Permissions
Published
2026-09-04T13:17Z
References (2)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 09:04Z
    PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM…
    cvelistv5