PT-2026-61547 · Bizerba · Brain2
CVE-2026-16246
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
BRAIN2 versions prior to 3.09
Description
During setup, the application
LogPathConfig.exe is executed, which incorrectly grants the Windows group Everyone full control over the %ProgramData% directory instead of restricting access to %ProgramData%BizerbaBRAIN2. While the main setup no longer executes this tool starting with version 3.09, the optional Bizerba ScriptService component continues to do so.Recommendations
Update to version 3.09 or later to prevent the setup from executing the vulnerable tool.
Disable or remove the Bizerba ScriptService component, as it remains vulnerable and is deprecated in version 3.11.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brain2