ZeroHour

CVE-2026-81302

niche

Local Privilege Escalation to SYSTEM in PALLET CONTROL Products

CVSS 4.0
8.5 high
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-81302 is an incorrect default permission vulnerability (CWE-276) in PALLET CONTROL products, in which shipped file, service, or registry permissions are misconfigured in a way that local low-privileged users can abuse. A local attacker who can run code on a machine where an affected product is installed modifies or replaces privileged components via the weak default permissions, causing their code to run in the context of the Windows SYSTEM account. Successful exploitation yields full local privilege escalation to SYSTEM, giving the attacker complete control of the confidentiality, integrity, and availability of that host. Affected parties are any organizations running PALLET CONTROL on Windows servers or workstations where untrusted or low-privileged users have local access. As of publication there is no known exploitation: the flaw is not in CISA KEV, has no public proof-of-concept, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Identify hosts running PALLET CONTROL and restrict local interactive and remote-logon access on them to trusted administrative users, since exploitation requires local access. Check file, service, and registry permissions used by the product for overly permissive defaults, and apply vendor-supplied updates or corrected configurations as soon as they are announced via the JPCERT/CC advisory; monitor for vendor guidance because no fixed version numbers are available in the current data.

Affected
PALLET CONTROL (product family; multiple versions reported affected)
Estimated exposure
nichelikely hundreds to a few thousand on-premises installations; exact count unknown — PALLET CONTROL is a niche, vertical-market pallet/logistics control product typically deployed at a limited number of warehouse and distribution sites rather than on internet-facing infrastructure, so only site-local Windows hosts running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

Weakness
CWE-276
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.