Improper Access Control in Wellbia XIGNCODE3 Affects System Integrity
CVE-2026-15430

Currently unrated

Key Information:

Vendor

Wellbia

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-15430?

The improper access control in the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3, specifically in the xhunter2.sys component version 2026.6.1.192, potentially allows a local unprivileged attacker to escalate their privileges to the NT AUTHORITY\SYSTEM level. This vulnerability also poses risks of credential extraction from PPL-protected lsass.exe and the ability to terminate critical PPL-protected security processes, undermining system integrity and security.

Affected Version(s)

XIGNCODE3 2026.6.1.192

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.