CVE-2026-102262
7
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Newell Brands | DYMO ID | 1.5.1.71 < 1.6.0 | affected |
| Newell Brands | DYMO ID | 1.6.0 | unaffected |
Weaknesses
- CWE-668: CWE-668 Exposure of Resource to Wrong Sphere
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://mediaserver.newellrubbermaid.com/industrial/Help/win/en/Content/What’s%20New.htm
- https://www.dymo.com/support?cfid=user-guide
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-275-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-102262
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.