CVE-2026-8920EPSS p1.3%
CVE-2026-8920CVE-2026-8920
Description
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .
Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Scoring
| EPSS | 0.11% probability of exploitation · percentile 1.3% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-15 |