← Back to CVE List
CVE-2026-8920NVD
Vulnerability Summary
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .
Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
CVSS v4.0 Base Metrics — Score 8.5 (HIGH)
Attack VectorLocal
Attack ComplexityHigh
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- ASUS Aura Wallpaper Service >= v2.1.8.0 and <= v2.1.15.0
- ASUS Aura Wallpaper Service v2.1.15.0