Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution has been reported yet.


Workaround

No workaround given by the vendor.

History

Tue, 21 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.
Title Search path without quotes in CivetWeb
Weaknesses CWE-428
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-04-21T14:32:09.961Z

Reserved: 2026-04-08T12:34:46.460Z

Link: CVE-2026-5789

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-21T15:16:37.713

Modified: 2026-04-21T16:20:24.180

Link: CVE-2026-5789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses