CVE-2026-15430: Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privi
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to
NT AUTHORITY\SYSTEM, extract credentials from PPL-protected
lsass.exe, and terminate PPL-protected security processes.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-15430
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15430 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Improper access control
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…nvd · 2026-08-03
- criticalCVE-2026-66803: Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code ove…nvd · 2026-07-30
- highCVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate othe…nvd · 2026-07-30
- criticalCVE-2026-41920: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traf…nvd · 2026-07-29
- lowCVE-2026-63236: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to…nvd · 2026-07-29
- lowCVE-2026-63235: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to…nvd · 2026-07-29
More from NVD Recent CVEs
- unknownCVE-2026-69249: python-cryptography is a package designed to expose cryptographic primitives and recipes to Py…2026-08-03
- unknownCVE-2026-69248: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-69247: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-67977: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2…2026-08-03
- unknownCVE-2026-67975: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index s…2026-08-03