RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 08 May 2026 07:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via PATH Environment Variable Exposure in RayVentory Scan Engine
Weaknesses CWE-730

Fri, 08 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-08T06:08:35.396Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-69599

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T07:16:28.617

Modified: 2026-05-08T07:16:28.617

Link: CVE-2025-69599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T07:30:03Z

Weaknesses