CVE-2026-16246 Details
Description
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the setup no longer executes this tool. However, the optional component Bizerba ScriptService still executes it. Bizerba ScriptService is being deprecated and will no longer be included starting with BRAIN2 version 3.11.
A vulnerability exists in Bizerba BRAIN2 versions prior to 3.09, where the application LogPathConfig.exe is executed during setup. This execution inadvertently grants the Windows group Everyone full control over the %ProgramData% directory, rather than restricting access to the intended subdirectory, %ProgramData%\Bizerba\BRAIN2. Although this issue was addressed in BRAIN2 version 3.09, it persists in the optional component Bizerba ScriptService, which will be deprecated in version 3.11. LogPathConfig.exe can also be executed during the setup of Bizerba_connect.BRAIN versions prior to 5.06, causing a similar incorrect permission assignment.
Users can manually review and restore the required permissions on the %ProgramData% directory, remove full control permissions for the Everyone group, and assign full control permissions specifically to the %ProgramData%\Bizerba\BRAIN2 directory. For Bizerba_connect.BRAIN users, full control permissions should be assigned to %ProgramData%\Bizerba_connect.BRAIN or %ProgramData%\Bizerba\BCT.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.bizerba.com/downloads/global/information-security/2026/bizerba-sa-2026-0003.pdf | bizerba |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | bizerba |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | bizerba |