CVE-2026-102262

Summary

Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.

Affected Software

VendorProductVersion RangeStatus
Newell BrandsDYMO ID1.5.1.71 < 1.6.0affected
Newell BrandsDYMO ID1.6.0unaffected

Weaknesses

  • CWE-668: CWE-668 Exposure of Resource to Wrong Sphere
  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

References