CVE-2026-102262: Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control

Published Oct 5, 2026
·
Updated

Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.

Affected Software

1 affected component
Newell Brands DYMO ID=1.5.1.71

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Newell Brands DYMO ID to a version that resolves this vulnerability.

    Fixed in 1.6.0

Event History

Oct 5, 2026
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Users running DYMO ID 1.5.1.71 who open a crafted job file are exposed. Successful exploitation runs code at the privilege level of the user who clicks the file.

2

What must an attacker provide or persuade a victim to do?

The attacker must place a job file alongside malicious modules or DLLs and induce a victim to click the job file. Opening the file causes the process working directory to be set to the job file's folder, allowing the malicious modules to be resolved.

3

What should be done if the affected version is deployed?

Update DYMO ID to version 1.6.0, which fixes the issue. Until updated, avoid opening job files from untrusted locations or sources, especially where accompanying files may be present.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203