Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 5.10.10.45 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Empia Technology
Empia Technology avacast |
|
| Vendors & Products |
Empia Technology
Empia Technology avacast |
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts. | |
| Title | eMPIA Technology|AVACAST - Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-04-28T12:12:53.229Z
Reserved: 2026-04-28T06:55:28.885Z
Link: CVE-2026-7280
Updated: 2026-04-28T12:12:49.509Z
Status : Deferred
Published: 2026-04-28T10:16:04.263
Modified: 2026-04-28T20:22:38.260
Link: CVE-2026-7280
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:10:55Z