Junglewise Threat Intelligence

CVE-2026-59683: OpenRGB network protocol arbitrary file write via attacker-controlled strings

CVE-2026-59683 · Severity: critical · CVSS 9.8 · Published 2026-08-26

Technologies: Adam Honse OpenRGB. Vendors: Adam Honse.

Executive brief

OpenRGB is a lighting control utility that communicates via a network protocol. An attacker can exploit a path traversal flaw in this protocol to write arbitrary content to any file location on the system. If the OpenRGB daemon runs as root or with elevated privileges, this enables complete system compromise; if running as a regular user, it allows full account takeover through file manipulation (e.g., modifying shell configuration files or SSH keys).

Technical details

The vulnerability is a path traversal and arbitrary file write flaw in OpenRGB's network protocol handler. The root cause is insufficient input validation on user-supplied profile names and file paths passed through the network protocol, allowing attackers to inject path traversal sequences (e.g., "../") to write files outside intended directories. The attack is network-accessible if the daemon is exposed (originally bound to 0.0.0.0, though the fix changes the default to 127.0.0.1), and requires no authentication. Attackers can write attacker-controlled strings to arbitrary filesystem paths, enabling code execution, privilege escalation, or account compromise depending on daemon privilege level. The fix (commit d2dd9dcc, August 2026) introduces a make_filename() function to sanitize profile names by removing dangerous characters and path traversal sequences before filesystem operations.

Affected products

  • Adam Honse OpenRGB prior to rc3 (August 2026)

Timeline

  • 2026-08-26: disclosed: CVE-2026-59683 published on NVD
  • 2026-08-12: patched: Fix applied in release_candidate_1.0rc3 (commit d2dd9dcc)

References

Related threats