What is CVE-2026-18759?
This vulnerability exists in the background service of ABP or AES, which runs as NT AUTHORITY\SYSTEM and uses an IPC mechanism with AES encryption. Because the encryption key file is readable by standard users, any authenticated local user could potentially recover it and execute commands with SYSTEM privileges. Restricting access permissions on the key file is recommended to mitigate the risk.
Azərbaycanca: Bu zəiflik ABP və ya AES proqramlarının arxa fon xidmətində aşkarlanıb. Şifrələmə açar faylı standart istifadəçilər tərəfindən oxuna bildiyindən, istənilən lokal autentifikasiya olunmuş istifadəçi NT AUTHORITY\SYSTEM səviyyəsində əmrlər icra edə bilər. Bu problemi aradan qaldırmaq üçün açar faylının giriş icazələrini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
What is the root cause of CVE-2026-18759?
The vulnerability exists because the encryption key file used by the background service of ABP or AES is readable by standard users.
What privileges can a local attacker gain by successfully exploiting CVE-2026-18759?
A local authenticated user who successfully exploits this vulnerability can execute commands with NT AUTHORITY\SYSTEM privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.