Local Privilege Escalation Vulnerability in Acunetix for Windows
CVE-2026-6958
Key Information:
- Vendor
Invicti Security Corp.
- Status
- Vendor
- CVE Published:
- 4 September 2026
Badges
What is CVE-2026-6958?
A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placing a malicious executable at the expected path. When the SYSTEM-level wvsc.exe process loads this file, it allows attackers to execute arbitrary code with elevated privileges, leading to potential system compromise.
Affected Version(s)
Acunetix 25.11.251107123
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
