CVE-2025-59887
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.27%
- CWE
- CWE-427
- Published
- 2025-12-26
- Last modified
- 2026-03-13
Affected products
- Eaton Eaton UPS Companion Software
Weakness type
Related vulnerabilities
- CVE-2019-25268 — NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution
- CVE-2025-65118 — AVEVA Process Optimization Uncontrolled Search Path Element
- CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l
- CVE-2025-30248 — DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t
- CVE-2026-29610 — OpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH Handling
- CVE-2026-24502 — Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit
- CVE-2025-33208 — NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
- CVE-2026-28456 — OpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path Handling