Junglewise Threat Intelligence

CVE-2026-81302: JAL Digital PALLET CONTROL privilege escalation in inter-process communication

CVE-2026-81302 · Severity: high · CVSS 7.8 · Published 2026-09-04

Executive brief

PALLET CONTROL is a Windows-based PC management and asset management tool used by enterprises to manage client systems. The product contains an improper access control vulnerability in its background service programs that allows any logged-in user to execute arbitrary code with SYSTEM privileges, potentially leading to complete system compromise and lateral movement across a corporate environment.

Technical details

The vulnerability is an improper access control flaw (CWE-276) in inter-process communication (IPC) mechanisms used by PALLET CONTROL background service programs. Non-administrative users can access these SYSTEM-privileged services without proper authorization, enabling privilege escalation. The attack requires local access (user must be logged into the affected Windows client), but no special privileges or user interaction are needed to exploit it once access is gained. An attacker can execute arbitrary code with SYSTEM privileges. Patches are available: PALLET CONTROL Ver. 6.3 patch 6 or later, PalletControl 10 Update 9 or later, and PalletControl Cloud (Update 9) or later.

Affected products

  • JAL Digital PALLET CONTROL 6.3 patch 5 and earlier
  • JAL Digital PalletControl 10 Update 8 and earlier
  • JAL Digital PalletControl Cloud 10 Update 8 and earlier

Timeline

  • 2026-09-01: disclosed: JVN advisory published
  • 2026-09-01: patched: PALLET CONTROL Ver. 6.3 patch 6+, PalletControl 10 Update 9+, PalletControl Cloud Update 9+ released

References