# CVE-2026-4415

## Summary

- **CVE ID:** CVE-2026-4415
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-23
- **Published:** Mar 30, 2026
- **Last Modified:** Mar 31, 2026

## Description

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

## Affected Products

- GIGABYTE — Gigabyte Control Center (0)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-10803-ae014-1.html)
- [CNA](https://www.twcert.org.tw/en/cp-139-10804-689cd-2.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.99%
- **EPSS Percentile:** 60.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._