CVE-2026-9169: LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9169?
CVE-2026-9169 has a high severity score of 8.8.
How do I fix CVE-2026-9169?
To mitigate CVE-2026-9169, update to the latest version of LUCID Vision Labs Arena SDK, version 1.0.85.11 or later.
What impact does CVE-2026-9169 have on my system?
CVE-2026-9169 allows a local attacker to execute arbitrary code with the privileges of the Arena SDK application.
Who is affected by CVE-2026-9169?
CVE-2026-9169 affects users of LUCID Vision Labs Arena SDK version 1.0.80.49 on Windows.
What type of attack is associated with CVE-2026-9169?
CVE-2026-9169 is associated with DLL Search Order Hijacking, which enables code execution through malicious DLLs.