Junglewise Threat Intelligence

CVE-2026-2998: eAI Technologies ERP F2 DLL hijacking

CVE-2026-2998 · Severity: high · CVSS 7.8 · Published 2026-02-23

Executive brief

eAI Technologies ERP F2, a business management software suite, contains a security flaw that could allow a user with local access to the system to run unauthorized programs. By placing a malicious file in the application's folder, an attacker can take control of the software's operations, potentially leading to data theft or system disruption. This risk is particularly relevant in shared computing environments where multiple users have access to the same workstation or server.

Technical details

A DLL hijacking vulnerability (CWE-426: Untrusted Search Path) exists in eAI Technologies ERP F2. The application fails to properly validate or specify the absolute path when loading dynamic-link libraries (DLLs), allowing it to load files from its own execution directory. An authenticated local attacker with permissions to write to the program directory can plant a maliciously crafted DLL file. When the ERP application is launched, it loads the attacker's DLL instead of the intended system library, resulting in arbitrary code execution with the privileges of the application user. Users are advised to upgrade to ERP F10 (PowerBuilder 2025 version).

Affected products

  • eAI Technologies (漢門科技) ERP F2 F2

Timeline

  • 2025-10-01: disclosed: Initial discovery by CHT Security Red Team
  • 2026-02-23: advisory: TWCERT/CC published advisory and assigned CVE-2026-2998
  • 2026-02-23: patched: Fix available in ERP F10 (PowerBuilder 2025 version)

References