CVE-2026-102262
Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
| CWE | CWE-668 CWE-22 |
| Vendor | newell brands |
| Product | dymo id |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for newell brands dymo id
Be the first to know when new high vulnerabilities affecting newell brands dymo id are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Newell Brands / DYMO ID
1.5.1.71 < 1.6.0
References
mediaserver.newellrubbermaid.com: https://mediaserver.newellrubbermaid.com/industrial/Help/win/en/Content/What's%20New.htm dymo.com: https://www.dymo.com/support?cfid=user-guide raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-275-01.json cve.org: https://www.cve.org/CVERecord?id=CVE-2026-102262
Credits
Paweล Karwowski, GetResponse S.A. Bartosz Nowicki, GetResponse S.A.