Uncontrolled Search Path Element in Evope Collector
Collector versión 1.1.6.9.0, Core: 1.1.3.2.4, Update: 1.1.0.3.6 – Models: Evope.Service.exe and wtsapi32.dll
INCIBE has coordinated the publication of a high severity vulnerability affecting Evope Collector, platform to accelerate business innovation. The vulnerability was discovered by Javier Sanz Martín.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-7169: CVSS v4.0: 7.5 | CVSS /AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-427
The vulnerability has been fixed by Evope team in version 1.1.7.13.
CVE-2026-7169: a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-7169 | Alta | No | Evope Collector |


