PT-2026-61547 · Bizerba · Brain2

CVE-2026-16246

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions BRAIN2 versions prior to 3.09
Description During setup, the application LogPathConfig.exe is executed, which incorrectly grants the Windows group Everyone full control over the %ProgramData% directory instead of restricting access to %ProgramData%BizerbaBRAIN2. While the main setup no longer executes this tool starting with version 3.09, the optional Bizerba ScriptService component continues to do so.
Recommendations Update to version 3.09 or later to prevent the setup from executing the vulnerable tool. Disable or remove the Bizerba ScriptService component, as it remains vulnerable and is deprecated in version 3.11.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16246

Affected Products

Brain2