PT-2026-26067 · Arturia · Software Center
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2026-24063
CVSS v3.1
8.2
High
| AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper gets instructed to execute this script. When the bash script is manipulated by an attacker this scenario will lead to privilege escalation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Software Center