CVE-2026-19191
StableBit · DrivePool
StableBit DrivePool 2.3.13.1687 is susceptible to local privilege escalation due to permission issues and insecure deserialization flaws.
Executive summary
A local privilege escalation vulnerability in StableBit DrivePool 2.3.13.1687 allows attackers to gain unauthorized elevated access to the host system.
Vulnerability
This vulnerability stems from permission issues (CWE-275) and incorrect privilege assignment (CWE-266). The flaw specifically enables local privilege escalation via insecure deserialization, allowing an attacker with local access to execute code with higher privileges than intended.
Business impact
The CVSS score of 7.8 reflects the high severity of this local privilege escalation flaw. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for an attacker to maintain persistence on the host, which is particularly concerning for storage management software that often handles critical data.
Remediation
Immediate Action: Update to the latest version of StableBit DrivePool as soon as the vendor provides a patch to address the deserialization and permission vulnerabilities.
Proactive Monitoring: Monitor for unusual service behavior or attempts to access administrative functions by non-privileged accounts.
Compensating Controls: Limit local system access to authorized personnel only and monitor the execution of administrative scripts or binaries associated with the software.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists.
Analyst recommendation
The presence of a public proof-of-concept elevates the urgency of this vulnerability. Organizations should prioritize updating their StableBit DrivePool installations to the latest version to mitigate the risk of local privilege escalation and subsequent system compromise.