Uncontrolled Search Path Element in Evope Collector

Posted date 27/04/2026
Identificador
INCIBE-2026-664
Importance
4 - High
Affected Resources

Collector versión 1.1.6.9.0, Core: 1.1.3.2.4, Update: 1.1.0.3.6 – Models: Evope.Service.exe and wtsapi32.dll   

Description

INCIBE has coordinated the publication of a high severity vulnerability affecting Evope Collector, platform to accelerate business innovation. The vulnerability was discovered by Javier Sanz Martín.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-7169: CVSS v4.0: 7.5 | CVSS /AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-427
Solution

The vulnerability has been fixed by Evope team in version 1.1.7.13.

Detail

CVE-2026-7169: a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-7169 Alta No Evope Collector
References list