Elevation of Privilege Vulnerability in NortheBridge LuminalShine for Moonlight
CVE-2026-50544

6.3MEDIUM

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2026-50544?

A latent elevation of privilege vulnerability exists in NortheBridge LuminalShine, a game stream host for Moonlight, prior to version 26.05.0-rc4. This vulnerability arises from the file located at C:\ProgramData\LuminalShine\config\apps.json, which is created by the SYSTEM service. Due to the default access control settings on Windows, BUILTIN\Users group is restricted to Read and Execute permissions only, thus not allowing write access and preventing the typical escalation scenario on a standard installation. Users are advised to update to the patched version 26.05.0-rc4 or to use default condition DACLs for ProgramData as a mitigation strategy.

Affected Version(s)

luminalshine < 26.05.0-rc4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.