๐Ÿ” CVE Alert

CVE-2026-19191

HIGH 7.8

StableBit DrivePool DrivePoolService DrivePool.Service.exe permission

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.

CWE CWE-275 CWE-266
Vendor stablebit
Product drivepool
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for stablebit drivepool

Be the first to know when new high vulnerabilities affecting stablebit drivepool are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

StableBit / DrivePool
2.3.13.1687

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386709 vuldb.com: https://vuldb.com/vuln/386709/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19191 vuldb.com: https://vuldb.com/submit/864539 winslow1984.com: https://winslow1984.com/books/cve-collection/page/stablebit-drivepool-23131687-local-privilege-escalation-via-insecure-deserialization

Credits

๐Ÿ” winslow1984 (VulDB User)