DLL Search Order Hijacking in LUCID Vision Labs Arena SDK on Windows
CVE-2026-9169

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-9169?

This vulnerability in LUCID Vision Labs Arena SDK allows local attackers to exploit a DLL search order hijacking flaw. By placing a malicious DLL in a directory included in the user-controlled PATH environment variable, attackers can execute arbitrary code with the same privileges as the application. The vulnerability arises when the SDK fails to find necessary dependencies locally and traverses the PATH to locate them. This flaw emphasizes the need for secure coding practices and proper validation of loaded libraries to mitigate potential security risks.

Affected Version(s)

Arena SDK Windows 1.0.80.49

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Nemeth at Oneconsult AG
.