CVE-2026-8920
Deferred Deferred - Pending Action

Improper File Path Handling in Aura Wallpaper Service

Vulnerability report for CVE-2026-8920, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: ASUS

Description

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the 'Β Security Update for Aura Wallpaper ServiceΒ ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus aura_wallpaper_service *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-923 The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper restrictions in the Aura Wallpaper Service that allow a local user to bypass path restrictions by sending crafted commands with an arbitrary file path. This can lead to unauthorized file operations.

Detection Guidance

Detection of this vulnerability requires checking for unauthorized file operations or bypass attempts in the Aura Wallpaper Service. Monitor logs for suspicious commands containing arbitrary file paths. Review ASUS security updates for patches or mitigations.

Impact Analysis

A local attacker could exploit this to perform unauthorized file operations on your system, potentially accessing or modifying sensitive files. This may disrupt normal system functions or cause instability in the Aura Wallpaper Service.

Compliance Impact

The vulnerability involves improper file path handling and communication channel restrictions, which could lead to unauthorized file operations. This may impact compliance with standards requiring strict access controls and data integrity, such as GDPR or HIPAA, by potentially allowing unauthorized access or modification of sensitive files.

Mitigation Strategies

Update to the latest version of the Aura Wallpaper Service as per the ASUS Security Advisory. Disable or restrict local user access to the service if not required. Monitor for unusual file operations or service disruptions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8920. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart