Arbitrary File Write Vulnerability in OpenRGB by CalcProgrammer1
CVE-2026-59683

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-59683?

The OpenRGB network protocol is susceptible to a vulnerability that enables attackers to write strings controlled by them into arbitrary file system paths. This flaw can lead to significant security risks, including unauthorized access to the system or complete account compromise, depending on the context in which the OpenRGB daemon operates (either as root or user).

Affected Version(s)

OpenRGB 0 <= 1.0rc3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.