Full Control Vulnerability in BRAIN2 by Bizerba
CVE-2026-16246
7.3HIGH
What is CVE-2026-16246?
In earlier versions of the BRAIN2 application (versions prior to 3.09), a setup executable named LogPathConfig.exe unintentionally granted the Windows group 'Everyone' full control over the %ProgramData% directory, instead of limiting access to %ProgramData%\Bizerba\BRAIN2. This security oversight exposes the system to potential unauthorized access. While BRAIN2 version 3.09 mitigates this issue by discontinuing the execution of LogPathConfig.exe during setup, the optional Bizerba ScriptService component continues to utilize this executable, posing further risks. It's important to note that Bizerba ScriptService will be deprecated and removed in BRAIN2 version 3.11.
Affected Version(s)
BRAIN2 Windows >3.09
