๐Ÿ” CVE Alert

CVE-2026-50544

MEDIUM 6.3

NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and is created by the `SYSTEM` service. Under Windows' default `C:\ProgramData` inheritance, that gives `BUILTIN\Users` only Read+Execute โ€” not writable โ€” so the canonical EoP doesn't actually trigger on a vanilla install. Version 26.05.0-rc4 contains a patch for the issue. As a workaround, use default condition DACLs for `ProgramData`.

CWE CWE-379 CWE-732
Vendor northebridge
Product luminalshine
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for northebridge luminalshine

Be the first to know when new medium vulnerabilities affecting northebridge luminalshine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

NortheBridge / luminalshine
< 26.05.0-rc4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NortheBridge/luminalshine/security/advisories/GHSA-52q6-5x97-2747