OpenRGB 网络协议允许将攻击者控制的字符串写入任意文件系统路径(这是 CVE-2026-59682 漏洞的扩展)。该漏洞可能导致以下后果:如果守护进程以 root 权限运行,则可能导致本地或远程的完整系统 compromised(即系统被完全控制);如果守护进程以用户上下文运行,则可能导致完整的账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CalcProgrammer1 | OpenRGB | ≤ 1.0rc3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CalcProgrammer1 | OpenRGB | 0 ~ 1.0rc3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59682 | 9.1 CRITICAL | Arbitrary file overwrite and deletion local and remote in OpenRGB |
| CVE-2026-18794 | 8.2 HIGH | OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and ove |
No comments yet