Junglewise Threat Intelligence

CVE-2026-3609: Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides a

CVE-2026-3609 · Severity: high · CVSS 7.8 · Published 2026-05-11

Executive brief

A security vulnerability exists in the XIGNCODE3 anti-cheat software, which is commonly used in online video games to prevent hacking. A flaw in its core system driver allows a standard user on a computer to gain full administrative control over the system. This could allow an attacker or malicious software already on the machine to bypass security protections, access sensitive data, or permanently compromise the operating system.

Technical details

A local privilege escalation vulnerability exists in the Wellbia XIGNCODE3 kernel-mode driver, xhunter1.sys. The driver improperly exposes the IRP_MJ_REITS command interface to non-privileged users. By interacting with this interface, a local attacker can request and obtain PROCESS_ALL_ACCESS rights to any process running on the system. This allows a low-privileged user process to manipulate higher-privileged processes or the kernel environment, leading to a full system compromise. The vulnerability is categorized as a failure to properly restrict access to a critical driver function.

Affected products

  • Wellbia XIGNCODE3 (xhunter1.sys)

Timeline

  • 2026-05-11: advisory: CVE-2026-3609 published by NVD

References