CVE-2026-6958
Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe)
CVSS
7.8
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 4, 2026 · Last modified: Sep 4, 2026 · CWE-427
Not enough EPSS history yet.
Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.
- olografix.orghttps://olografix.org/acme/_poc/CVE-2026-6958.pdf
- seclists.orghttps://seclists.org/fulldisclosure/2026/Sep/0
- www.acunetix.comhttps://www.acunetix.com/
- www.vulncheck.comhttps://www.vulncheck.com/advisories/acunetix-local-privilege-escalation-via-wvsc-exe
- seclists.orghttp://seclists.org/fulldisclosure/2026/Sep/0