CVE-2026-8921: High severity ASUS ASUS Business Manager vulnerability
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8921?
The severity of CVE-2026-8921 is rated as high with a CVSS score of 8.5.
How can I fix CVE-2026-8921?
To fix CVE-2026-8921, apply the security update available for ASUS Business Manager as detailed in the security advisory.
What types of privileges can be escalated due to CVE-2026-8921?
CVE-2026-8921 allows a local user to execute arbitrary code with SYSTEM privileges.
What is the nature of the vulnerability in CVE-2026-8921?
CVE-2026-8921 is an external control of file name or path vulnerability that can be exploited via a tampered IPC message.
Who is affected by CVE-2026-8921?
Users of ASUS Business Manager are affected by CVE-2026-8921 due to the specific vulnerability in the software.