CVE-2026-4415
HIGHGIGABYTE|Gigabyte Control Center - Arbitrary File Write
Title source: cnaDescription
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.
Scores
CVSS v3
8.1
EPSS
0.0059
EPSS Percentile
69.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-23
CWE-787
Status
published
Products (2)
gigabyte/control_center
< 25.12.10.01
GIGABYTE/Gigabyte Control Center
< 25.07.21.01
Published
Mar 30, 2026
Tracked Since
Mar 30, 2026