ASUSCVE-2026-8920
ASUS Aura Wallpaper Service: local user could perform file operations
High8.5CVE-2026-8920 · Published Jul 15, 2026
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Aura Wallpaper Service Product | >= v2.1.8.0, <= v2.1.15.0 | No fix yet |
Details and references
More ASUS advisories
All ASUS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 15 | ASUS GameSDK: information disclosure | High7.2 | No fix yet |
| Jul 15 | ASUS Business Manager: untrusted pointer dereference | High8.4 | No fix yet |
| Jul 15 | ASUS Business Manager: out-of-bounds read | Medium5.6 | No fix yet |
| Jul 15 | ASUS Router: improper certificate validation | Critical9.5 | No fix yet |
| Jul 15 | ASUS Business Manager: information disclosure | High8.2 | No fix yet |
| Jul 15 | ASUS Router: SQL injection | Medium5.9 | No fix yet |