Back

HIGH

Vulnerability Related to an Uncontrolled Search Path Element in a UPS Management Application

Published Apr 15, 2026

Description

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges.

If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OMRON
Published Apr 15, 2026
Updated Apr 15, 2026
Reserved Apr 2, 2026
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a