CVE-2026-8164
HIGH
7.3
CVSS 3.1
Description
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.
This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
Metadata
Severity & Metrics
7.3
HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| ArkSigner Software and Hardware Industry and Trade Inc. | ArkSigner Desktop Client | — | v2.2.16.10 ≤ 17062026 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-427 | cna | CWE-427 Uncontrolled Search Path Element |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.3 | HIGH | 3.1 | cna | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |