CVE-2026-102262EPSS p10.4%
CVE-2026-102262CVE-2026-102262
Description
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Scoring
| CVSS | 7.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.21% probability of exploitation · percentile 10.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |