Vulnerability Description
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper gets instructed to execute this script. When the bash script is manipulated by an attacker this scenario will lead to privilege escalation.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-24063?
CVE-2026-24063 is a vulnerability with a CVSS score of 8.2 (HIGH). When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, m...
How severe is CVE-2026-24063?
CVE-2026-24063 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24063?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.