CVE-2026-15430

MEDIUM

Wellbia XIGNCODE3 - Privilege Escalation

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-15430. PoCs published by BlackSnufkin.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-15430, a Local Privilege Escalation (LPE) vulnerability in the AxHunter driver (xhunter1.sys). The exploit bypasses Process Protection Light (PPL) to obtain a privileged process handle and inject shellcode into a target process, achieving SYSTEM-level command execution via WinExec.

Description

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.

Exploits (1)

github WORKING POC
by BlackSnufkin · rustpoc
https://github.com/BlackSnufkin/AxHunter

This repository contains a functional exploit for CVE-2026-15430, a Local Privilege Escalation (LPE) vulnerability in the AxHunter driver (xhunter1.sys). The exploit bypasses Process Protection Light (PPL) to obtain a privileged process handle and inject shellcode into a target process, achieving SYSTEM-level command execution via WinExec.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: AxHunter driver (xhunter1.sys), likely version associated with CVE-2026-3609
Auth required
Prerequisites: Local access to the target system · AxHunter driver installed and loaded · Ability to interact with the driver device (\\.\xhunter) · Target process PID with sufficient privileges for handle duplication
mistral-large-3 · analyzed Aug 05, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.2
EPSS 0.0011
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269 CWE-284 CWE-732
Status published
Products (1)
Wellbia/XIGNCODE3 2026.6.1.192
Published Aug 03, 2026
Tracked Since Aug 03, 2026