CVE-2026-26306

HIGH

OM Workspace (Windows Edition) <=2.4 - DLL Hijacking

Title source: llm
STIX 2.1

Description

The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
OM Digital Solutions Corporation/OM Workspace (Windows Edition) Ver 2.4 and earlier
Published Mar 25, 2026
Tracked Since Mar 25, 2026