🔐 CVE Alert

CVE-2026-5397

HIGH 7.8

Vulnerability Related to an Uncontrolled Search Path Element in a UPS Management Application

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
1th

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup.

CWE CWE-427
Vendor omron social solutions co., ltd.
Product powerattendant standard edition
Published Apr 15, 2026
Last Updated Apr 15, 2026
Stay Ahead of the Next One

Get instant alerts for omron social solutions co., ltd. powerattendant standard edition

Be the first to know when new high vulnerabilities affecting omron social solutions co., ltd. powerattendant standard edition are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

OMRON SOCIAL SOLUTIONS CO., Ltd. / PowerAttendant Standard Edition
2.1.2 or lower

References

NVD ↗ CVE.org ↗ EPSS Data ↗
omron.com: https://www.omron.com/jp/ja/inquiry/data/OMSR-2026-001_ja.pdf omron.com: https://www.omron.com/global/en/inquiry/data/OMSR-2026-001_en.pdf