๐Ÿ” CVE Alert

CVE-2026-6958

HIGH 7.8

Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.

CWE CWE-427
Vendor invicti security corp.
Product acunetix
Published Sep 4, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for invicti security corp. acunetix

Be the first to know when new high vulnerabilities affecting invicti security corp. acunetix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Invicti Security Corp. / Acunetix
25.11.251107123

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
seclists.org: https://seclists.org/fulldisclosure/2026/Sep/0 olografix.org: https://olografix.org/acme/_poc/CVE-2026-6958.pdf acunetix.com: https://www.acunetix.com/ vulncheck.com: https://www.vulncheck.com/advisories/acunetix-local-privilege-escalation-via-wvsc-exe seclists.org: http://seclists.org/fulldisclosure/2026/Sep/0

Credits

Andrea Intilangelo