Incorrect Default Permissions in ArubaSign by Aruba Networks
CVE-2026-12602

8.8HIGH

Key Information:

Vendor

Aruba

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-12602?

The vulnerability in ArubaSign arises from incorrect default permissions assigned during installation. Specifically, versions before v4.6.6 allow excessive permissions for the 'Everyone' group on critical files located in C:\Program Files. This misconfiguration allows unprivileged users to potentially replace the main executable and its components with malicious files. If exploited, a malicious actor could execute arbitrary code with elevated privileges, risking complete compromise of the system and jeopardizing both security and data integrity.

Affected Version(s)

ArubaSign 0 < 4.6.6

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Intilangelo (acme)
.