Vulnerability Description
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-8920?
CVE-2026-8920 is a documented vulnerability. Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted...
How severe is CVE-2026-8920?
CVSS scoring is not yet available for CVE-2026-8920. Check NVD for updates.
Is there a patch for CVE-2026-8920?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.