Access Control Vulnerability in ExpressUpdate Agent for Windows by NEC
CVE-2026-8797

8.5HIGH

Key Information:

Vendor
CVE Published:
26 June 2026

What is CVE-2026-8797?

An access control deficiency has been identified in the ExpressUpdate Agent for Windows, which could allow a malicious user to exploit the product. If they gain access, it may lead to arbitrary code execution with SYSTEM privileges, posing a significant risk to the system’s integrity and security. This vulnerability highlights the need for robust security measures to mitigate unauthorized access and protect sensitive data.

Affected Version(s)

ExpressUpdate Agent for Windows 3.24 and prior

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MASAHIRO IIDA of LAC Co., Ltd.
.