Junglewise Threat Intelligence

CVE-2026-32680: RATOC RAID Monitoring Manager privilege escalation via insecure ACLs

CVE-2026-32680 · Severity: high · CVSS 7.8 · Published 2026-03-26

Executive brief

RATOC RAID Monitoring Manager is a utility used to manage and monitor RAID storage hardware. A security flaw in its installer allows non-administrative users to modify files within the application's folder if a custom installation path was chosen. This could allow a local attacker to gain full control over the computer, potentially leading to data theft or system-wide disruption.

Technical details

The vulnerability is classified as Incorrect Default Permissions (CWE-276). When a user chooses a non-default installation directory during setup, the installer fails to restrict write permissions on the resulting folder. A local attacker with low-level privileges can replace legitimate application binaries or DLLs with malicious code. Because the application or its associated services may run with elevated privileges, this allows the attacker to execute arbitrary code as SYSTEM. The issue is resolved in version 2.00.009.260220.

Affected products

  • RATOC Systems, Inc. RAID Monitoring Manager for Windows versions prior to 2.00.009.260220

Timeline

  • 2025-08-29: other: Initial vendor notification/internal discovery date mentioned in Japanese advisory
  • 2026-03-26: disclosed: Public disclosure via JVN and NVD
  • 2026-03-26: patched: Fixed version 2.00.009.260220 released

References