Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution has been reported yet.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration. | |
| Title | Search path without quotes in CivetWeb | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-04-21T14:32:09.961Z
Reserved: 2026-04-08T12:34:46.460Z
Link: CVE-2026-5789
No data.
Status : Awaiting Analysis
Published: 2026-04-21T15:16:37.713
Modified: 2026-04-21T16:20:24.180
Link: CVE-2026-5789
No data.
OpenCVE Enrichment
No data.
Weaknesses