CVE-2026-32680
Deferred
Deferred - Pending Action
Insecure ACLs in RATOC RAID Installer Enables SYSTEM Code Execution
Publication date: 2026-03-26
Last updated on: 2026-05-19
Assigner: JPCERT/CC
Description
Description
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to execute an arbitrary code with SYSTEM privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ratoc | raid_monitoring_manager | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |