CVE-2026-3315
Analyzed
Analyzed - Analysis Complete
Incorrect Permissions in ASSA ABLOY Visionline Allow Privilege Escalation
Publication date: 2026-03-10
Last updated on: 2026-05-07
Assigner: National Cyber Security Centre Finland
Description
Description
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| assaabloy | visionline | From 1.0.0 (inc) to 1.34.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
| CWE-250 | The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. |
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |