CVE-2026-4415 is an Arbitrary File Write vulnerability in GIGABYTE's Gigabyte Control Center, affecting systems where the pairing feature is enabled. Rated 8.1 HIGH, this flaw allows unauthenticated remote attackers to write arbitrary files to any location on the operating system. Exploitation, despite high attack complexity, can lead to arbitrary code execution or privilege escalation. While there are no known active exploits, public exploit code, or KEV entries, the vulnerability is garnering community attention, with discussions advising users to disable the pairing feature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.12.10.01CPE matchmatch criteria | cpe:2.3:a:gigabyte:control_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.