CVE-2026-32680 Details
Description
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to execute an arbitrary code with SYSTEM privilege.
A vulnerability exists in the installer of RATOC RAID Monitoring Manager for Windows, prior to version 2.00.009.260220, allowing non-administrative users to execute arbitrary code with SYSTEM privileges. This issue arises when the installation folder is customized to a non-default location, leaving the folder with insecure access control lists (ACLs) that permit modification of its contents by non-administrative users.
Users are advised to update RATOC RAID Monitoring Manager for Windows to version 2.00.009.260220 or later. Instructions for updating are available on the RATOC Systems website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2026CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN08057419/ | [email protected] | AdvisoryBundleRemedy |
| https://www.ratocsystems.com/topics/userinfo/raidmanager202508/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RATOC RAID Monitoring Manager | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | New CVE Received | [email protected] |
Volerion