# CVE-2026-19397

## Summary

- **CVE ID:** CVE-2026-19397
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-306
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the ' 
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.

## Affected Products

- ASUS — Control Center Express Agent (0)

## References

- [CNA](https://www.asus.com/security-advisory)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._