Authentication Bypass in ASUS Control Center Express Agent
CVE-2026-19397

7.7HIGH

Key Information:

Vendor

Asus

Vendor
CVE Published:
8 September 2026

What is CVE-2026-19397?

A vulnerability exists in the ASUS Control Center Express Agent that allows unauthenticated users within proximity to gain control over the host system. This occurs when the host is maintaining an active session, enabling access to critical functions without proper authentication. This flaw poses a significant security risk as it can lead to unauthorized actions on the affected host. For further details, please consult the ASUS Security Advisory.

Affected Version(s)

Control Center Express Agent 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0x0dee
.