CVE-2026-50544
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Summary
NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at src/platform/windows/misc.cpp lives at C:\ProgramData\LuminalShine\config\apps.json and is created by the SYSTEM service. Under Windows' default C:\ProgramData inheritance, that gives BUILTIN\Users only Read+Execute — not writable — so the canonical EoP doesn't actually trigger on a vanilla install. Version 26.05.0-rc4 contains a patch for the issue. As a workaround, use default condition DACLs for ProgramData.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NortheBridge | luminalshine | < 26.05.0-rc4 | affected |
Weaknesses
- CWE-379: CWE-379: Creation of Temporary File in Directory with Insecure Permissions
- CWE-732: CWE-732: Incorrect Permission Assignment for Critical Resource
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.