IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
[POC] CVE-2026-49176 — CVE-2026-49176_LPE_POC
Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-49176_BOF
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free