Uncontrolled Search Path Element Vulnerability in ArkSigner Desktop Client by ArkSigner Software and Hardware Industry and Trade Inc.
CVE-2026-8164

7.3HIGH

What is CVE-2026-8164?

The vulnerability in ArkSigner Desktop Client allows an attacker to exploit the uncontrolled search path element, leading to search order hijacking. This occurs when a malicious actor can manipulate the search path that the application uses to locate executable files. As a result, it may execute unintended and potentially dangerous code, compromising the integrity and security of the system. This vulnerability impacts multiple versions of ArkSigner Desktop Client, making timely updates and patches essential for users to mitigate risks effectively.

Affected Version(s)

ArkSigner Desktop Client v2.2.16.10 <= 17062026

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alperen KESKİN
.