It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges.
If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Omron
Omron powerattendant Standard Edition |
|
| Vendors & Products |
Omron
Omron powerattendant Standard Edition |
Wed, 15 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup. | |
| Title | Vulnerability Related to an Uncontrolled Search Path Element in a UPS Management Application | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OMRON
Published:
Updated: 2026-04-15T16:13:26.313Z
Reserved: 2026-04-02T00:17:38.524Z
Link: CVE-2026-5397
Updated: 2026-04-15T13:46:44.852Z
Status : Received
Published: 2026-04-15T05:16:45.740
Modified: 2026-04-15T05:16:45.740
Link: CVE-2026-5397
No data.
OpenCVE Enrichment
Updated: 2026-04-15T14:53:31Z