HIGH 7.0 NVD
CVE-2026-102262
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside mal
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
References
- https://mediaserver.newellrubbermaid.com/industrial/Help/win/en/Content/What's%20New.htm
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-275-
- https://www.cve.org/CVERecord?id=CVE-2026-102262
- https://www.dymo.com/support?cfid=user-guide
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.