CVE-2026-8920: High severity ASUS Aura Wallpaper Service vulnerability
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8920?
CVE-2026-8920 has a high severity rating of 8.5 according to the CVSS scoring system.
What does CVE-2026-8920 exploit?
CVE-2026-8920 exploits improper restriction of communication channels, allowing local users to bypass file path restrictions.
How can I fix CVE-2026-8920?
To fix CVE-2026-8920, update to the latest version of the ASUS Aura Wallpaper Service where this vulnerability has been addressed.
Who is affected by CVE-2026-8920?
Users of ASUS Aura Wallpaper Service are affected by CVE-2026-8920 due to its improper security controls.
What type of vulnerability is CVE-2026-8920?
CVE-2026-8920 is classified as a local file operations vulnerability allowing unauthorized file access.