CVE-2026-24694 PUBLISHED

Assigner: jpcert
Reserved: 27.01.2026 Published: 03.02.2026 Updated: 03.02.2026

The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the application.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Roland Corporation
Product Roland Cloud Manager
Versions
  • Version ver.3.1.19 and prior is affected

References

Problem Types