HIGHVulnerability

CVE-2026-9169

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-9169
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-07T09:16:59.430
last_modified
2026-08-26T16:39:50.787

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Search Path Element

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9169 — Ninja Signal Threat Intelligence | Ninja Signal