CVE-2026-59683: OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings
Published Aug 25, 2026
·Updated
The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context).
Affected Software
1 affected component
OpenRGB OpenRGB
Event History
Aug 26, 2026
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments have the greatest impact if exploited?
OpenRGB daemon instances running as root can lead to full system compromise. Instances running in a user context can lead to full account takeover for that user.
2
Does exploitation require authentication or user interaction?
The supplied severity vector indicates network access, low attack complexity, no privileges required, and no user interaction. The issue can be exploited locally or remotely when the relevant network protocol is reachable.