Executive brief
Seagull Software BarTender is a professional labeling and barcode software used by businesses to design and print labels. A critical security flaw allows an unauthenticated attacker to remotely take full control of the server hosting the software. This could lead to the theft of sensitive data, disruption of labeling operations, or the use of the server as a foothold to attack other parts of the corporate network.
Technical details
A remote code execution vulnerability exists in the .NET Remoting service (BtSystem.Service.exe) of BarTender 2010, 2016, and 2019, exposed on TCP port 7375. The service registers unauthenticated singleton endpoints (BarTenderSystem or DataServiceSingleton) configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. This configuration allows for insecure deserialization (unmarshalling) of untrusted data. An unauthenticated attacker can exploit this to read/write arbitrary files or coerce NTLMv2 authentication via UNC paths. Because the service runs with NT AUTHORITY\SYSTEM privileges, successful exploitation results in full system compromise.
Affected products
- Seagull Software BarTender 2010 <= 10.1 R4
- Seagull Software BarTender 2016 <= R9
- Seagull Software BarTender 2019 <= R10
Timeline
- 2026-06-04: disclosed
- 2026-06-04: advisory