Security Advisory

CVE-2026-8920

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-15 02:00:56
Last updated 2026-07-15 13:12:23
Assigner ASUS
CVSS score 8.5
State PUBLISHED

Description

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.