Incorrect Default Permissions in ArubaSign by Aruba Networks
CVE-2026-12602
8.8HIGH
What is CVE-2026-12602?
The vulnerability in ArubaSign arises from incorrect default permissions assigned during installation. Specifically, versions before v4.6.6 allow excessive permissions for the 'Everyone' group on critical files located in C:\Program Files. This misconfiguration allows unprivileged users to potentially replace the main executable and its components with malicious files. If exploited, a malicious actor could execute arbitrary code with elevated privileges, risking complete compromise of the system and jeopardizing both security and data integrity.
Affected Version(s)
ArubaSign 0 < 4.6.6
