Improper Permissions in Bizerba _connect.BRAIN Application
CVE-2026-16247
7.3HIGH
What is CVE-2026-16247?
In versions prior to 5.06 of the Bizerba _connect.BRAIN application, the setup process insecurely executes LogPathConfig.exe, which inadvertently deletes existing permissions on the %ProgramData% directory. This flaw grants the Windows group 'Everyone' full control over sensitive directories, such as %ProgramData%\Bizerba_connect.BRAIN and %ProgramData%\Bizerba\BCT. This misconfiguration poses a security risk, as it may expose critical data to unauthorized users. Bizerba has addressed this issue in version 5.06, where the problematic tool is no longer executed during setup.
Affected Version(s)
_connect.BRAIN Windows >5.06
