CVE-2026-8164

HIGH

Search Order Hijacking in ArkSigner's ArkSigner Desktop Client

Title source: cna
STIX 2.1

Description

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.

References (1)

Core 1
Core References

Scores

CVSS v3 7.3
EPSS 0.0011
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
ArkSigner Software and Hardware Industry and Trade Inc./ArkSigner Desktop Client v2.2.16.10 - 17062026
Published Jul 28, 2026
Tracked Since Jul 28, 2026