CVE-2026-56437

HIGH

Fuji Electric Co.,ltd. Pupsman - Uncontrolled Search Path Element

Title source: rule
STIX 2.1

Description

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
Fuji Electric Co.,Ltd./Pupsman prior to 3.9.0
Published Jul 08, 2026
Tracked Since Jul 08, 2026