8.8

CVE-2026-25264

Uncontrolled Search Path Element in Qualcomm Software Center

Privilege escalation due to weak configuration during package extraction process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Software Center Version 1.17.1
   Microsoft ≫ Windows Version -
Qualcomm ≫ Software Center Version 1.19.1
   Microsoft ≫ Windows Version -
Qualcomm ≫ Software Center Version 1.21.0
   Microsoft ≫ Windows Version -
Qualcomm ≫ Software Center Version 1.22.1
   Microsoft ≫ Windows Version -
Qualcomm ≫ Software Center Version 1.25.1
   Microsoft ≫ Windows Version -
Qualcomm ≫ Software Center Version 1.26.0
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.015
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Qualcomm 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html
Vendor Advisory