CVE-2026-16246 HIGH

CVE-2026-16246: Insecure permission assignment due to execution of LogPathConfig.exe during setup

Vendor Bizerba Se & Co. Kg
Product BRAIN2
Weakness CWE-276
Published July 20, 2026
Last update July 20, 2026

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the setup no longer executes this tool. However, the optional component Bizerba ScriptService still executes it. Bizerba ScriptService is being deprecated and will no longer be included starting with BRAIN2 version 3.11.

Key dates

02Disclosure timeline

July 20, 2026 CVE published
July 20, 2026 Record updated