CVE-2026-6958 Details
Description
Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.
A local privilege escalation vulnerability exists in Acunetix version 25.11.251107123 for Windows. The issue is located in the Web Vulnerability Scanning Engine (wvsc.exe), where a hardcoded directory path for OpenSSL-related files is missing by default. This flaw allows low-privileged local attackers to execute arbitrary code with SYSTEM privileges. Attackers can create the missing directory, place a malicious file at the expected location, and trigger the wvsc.exe process to load and execute it, leading to full privilege escalation.
Users are advised to update to the latest version of Acunetix where this vulnerability has been addressed. Additionally, the vendor should ensure that OpenSSL-related files are loaded from trusted, administrator-controlled directories and that filesystem permissions prevent unprivileged users from modifying directories used by privileged processes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Sep/0 | CVE | ExploitMailing ListTechnical Description |
| https://olografix.org/acme/_poc/CVE-2026-6958.pdf | [email protected] | Broken LinkExploit |
| https://seclists.org/fulldisclosure/2026/Sep/0 | [email protected] | ExploitMailing ListRemedy |
| https://www.acunetix.com/ | [email protected] | Vendor |
| https://www.vulncheck.com/advisories/acunetix-local-privilege-escalation-via-wvsc-exe | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Acunetix | ~25.11 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | CVE Modified | CVE |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion