Sceawere

Vulnerability Detail

CVE-2026-19190UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StableBit Scanner Service Permission Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
StableBit
Product
Scanner
Attack Type
Permission Issues
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-07T04:17:21.367Z",
  "pubdate": "2026-08-07T04:17:21.367Z",
  "executiveSummary": "A permission-related vulnerability has been identified within the ScannerService component of StableBit Scanner version 2.6.13.4088. This security weakness specifically affects the executable file located at C:\\Program Files (x86)\\StableBit\\Scanner\\Service\\Scanner.Service.exe. The flaw introduces improper access control or insecure file/object permissions, which can be leveraged locally to compromise system integrity or security postures.\nThe impact of this vulnerability centers around local privilege manipulation and unauthorized interaction with the affected service binary. An attacker must possess local execution capabilities on the target system to exploit the weakness, as network-based vectors are not applicable. Public availability of an exploit increases the immediate risk to unpatched installations.\nRisk implications include potential local privilege escalation, unauthorized modification of service binaries, or tampering with service execution flows depending on the exact misconfiguration of access control lists. Remediation requires strict adherence to secure software deployment practices and immediate vendor-supplied updates or manual ACL hardening.",
  "technicalDetails": "The vulnerability resides in the ScannerService component of StableBit Scanner 2.6.13.4088, specifically targeting the binary path C:\\Program Files (x86)\\StableBit\\Scanner\\Service\\Scanner.Service.exe. The root cause stems from weak or improperly configured Discretionary Access Control Lists (DACLs) associated with the service executable or its installation directory, allowing unauthorized local users or low-privileged processes to modify, replace, or improperly interact with the file.\nExploitation of this vulnerability requires local execution capabilities on the host operating system. Authentication requirements are minimal to none for the initial local access phase, provided the attacker can execute code or interact with the local file system. Because the attack vector is restricted to local execution, remote adversaries cannot exploit this flaw directly without prior compromise or access via secondary vectors such as remote desktop or SSH.\nThe attack flow typically proceeds in a structured manner. First, an authenticated or unprivileged local user identifies the overly permissive access controls on C:\\Program Files (x86)\\StableBit\\Scanner\\Service\\Scanner.Service.exe. Second, leveraging the inadequate permissions, the local attacker overwrites the legitimate service executable with a malicious binary or alters its contents. Third, upon system reboot, service restart, or manual invocation of the Scanner.Service.exe service, the operating system executes the malicious payload with the elevated privileges assigned to the service context, which often runs as SYSTEM or an administrative account.\nPost-exploitation impact includes arbitrary code execution with elevated system privileges, persistence mechanisms via service manipulation, and potential bypass of local security controls. Because an exploit has been made public, threat actors can readily automate the detection and exploitation of these improper permission settings across vulnerable environments."
}
CVE-2026-19190: StableBit Scanner Service Permission Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere