Improper Permissions in Bizerba _connect.BRAIN Application
CVE-2026-16247

7.3HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-16247?

In versions prior to 5.06 of the Bizerba _connect.BRAIN application, the setup process insecurely executes LogPathConfig.exe, which inadvertently deletes existing permissions on the %ProgramData% directory. This flaw grants the Windows group 'Everyone' full control over sensitive directories, such as %ProgramData%\Bizerba_connect.BRAIN and %ProgramData%\Bizerba\BCT. This misconfiguration poses a security risk, as it may expose critical data to unauthorized users. Bizerba has addressed this issue in version 5.06, where the problematic tool is no longer executed during setup.

Affected Version(s)

_connect.BRAIN Windows >5.06

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.