Junglewise Threat Intelligence

CVE-2026-8164: ArkSigner Desktop Client Search Order Hijacking

CVE-2026-8164 · Severity: high · CVSS 7.3 · Published 2026-07-28

Executive brief

ArkSigner Desktop Client, a tool used for digital signatures and secure document authentication, contains a vulnerability that could allow an attacker to take control of a user's computer. By placing a malicious file in a specific location on the system, an attacker can trick the software into running unauthorized code when the application starts. This could lead to the theft of sensitive data, unauthorized digital signing, or full system compromise if a user is persuaded to perform a specific action.

Technical details

The ArkSigner Desktop Client (versions v2.2.16.10 through 17062026) is vulnerable to an Uncontrolled Search Path Element (CWE-427) flaw, commonly known as Search Order Hijacking. The application fails to properly validate or restrict the paths used to load external resources or libraries, allowing a local attacker with low privileges to place a malicious DLL or executable in a directory searched by the application. If a legitimate user subsequently triggers the application, the malicious code is executed with the privileges of the user. This attack requires local access and some level of user interaction to succeed.

Affected products

  • ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client v2.2.16.10 through 17062026

Timeline

  • 2026-07-28: disclosed: Initial disclosure by TR-CERT
  • 2026-07-28: advisory: NVD publication date

References