CVE-2026-30266 is an insecure permissions vulnerability affecting DeepCool DeepCreative version 1.2.12 and earlier, which allows local attackers to execute arbitrary code through a specially crafted file. The vulnerability carries a HIGH severity rating with a CVSS score of 7.8, featuring a local attack vector with low complexity and no required privileges, resulting in high confidentiality, integrity, and availability impact. The exploit requires user interaction but can be executed without elevated permissions. Currently, there is no evidence of active exploitation in the wild, and the vulnerability is not listed on any public exploit databases or CISA's known exploited vulnerabilities catalog. The EPSS score indicates relatively low probability of exploitation compared to other CVEs, and the vulnerability remains inactive on public threat lists, suggesting limited community attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.12CPE matchmatch criteria | cpe:2.3:a:deepcool:deepcreative:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.