Unquoted Service Path Vulnerability in AVACAST by eMPIA Technology
CVE-2026-7280

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-7280?

AVACAST, developed by eMPIA Technology, is susceptible to an unquoted service path vulnerability. This flaw allows privileged local attackers to place a malicious executable file in a specific directory. When the AVACAST service is initiated, the service inadvertently executes the malicious file due to the absence of quotes in its file path. This can lead to arbitrary code execution with system privileges, potentially compromising the integrity of the system.

Affected Version(s)

AVACAST 0 <= 5.10.10.43

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.