Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://kb.cert.org/vuls/id/380058 |
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalrgb
Signalrgb signalrgb Kernel Driver |
|
| Vendors & Products |
Signalrgb
Signalrgb signalrgb Kernel Driver |
Fri, 19 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 19 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 18 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and issue privileged IOCTLs. | |
| Title | CVE-2026-8049 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-06-18T13:12:38.935Z
Reserved: 2026-05-06T17:40:03.996Z
Link: CVE-2026-8049
Updated: 2026-06-18T13:12:34.145Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:59Z