CVE-2026-12663: ControlFLASH ® – Improper Access Control
Published Sep 1, 2026
·Updated
A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
Affected Software
1 affected component
ControlFLASH™
Event History
Sep 1, 2026
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionWeakness
Frequently Asked Questions
1
Who could exploit this issue?
An attacker who can write to the affected ControlFLASH installation directory could place or modify code there. The resulting code execution occurs at the permission level of the logged-in user.
2
What access-control condition should defenders check for?
Check whether the ControlFLASH installation directory grants write permissions to the "Everyone" group. That permission is the condition described as enabling arbitrary code execution.