What is CVE-2026-9169?
CVE-2026-9169 is a DLL Search Order Hijacking vulnerability in LUCID Vision Labs Arena SDK version 1.0.80.49 on Windows. It allows a local attacker to achieve arbitrary code execution with the application's privileges by placing a malicious DLL in a user-controlled directory within the PATH environment variable. Affected users should update the SDK and ensure untrusted directories are not present in the PATH.
Azərbaycanca: CVE-2026-9169, LUCID Vision Labs Arena SDK 1.0.80.49 versiyasının Windows əməliyyat sistemində DLL Search Order Hijacking zəifliyidir. Bu, yerli təcavüzkara PATH mühit dəyişənindəki istifadəçi tərəfindən idarə olunan qovluğa zərərli DLL faylı yerləşdirməklə, tətbiqin imtiyazları ilə ixtiyari kod icra etməyə imkan verir. Təsirə məruz qalan istifadəçilər SDK-nı ən son versiyaya yeniləməli və etibarsız qovluqların PATH-da olmamasına diqqət etməlidir.
FAQ2
Which version of LUCID Vision Labs Arena SDK is affected by CVE-2026-9169?
CVE-2026-9169 affects version 1.0.80.49 of LUCID Vision Labs Arena SDK on Windows.
How can a local attacker achieve arbitrary code execution using CVE-2026-9169?
A local attacker can achieve arbitrary code execution through DLL Search Order Hijacking by placing a malicious DLL in a user-controlled directory within the PATH environment variable.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.