CVE-2026-26306 PUBLISHED

Assigner: jpcert
Reserved: 12.03.2026 Published: 25.03.2026 Updated: 25.03.2026

The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor OM Digital Solutions Corporation
Product OM Workspace (Windows Edition)
Versions
  • Version Ver 2.4 and earlier is affected

References

Problem Types