CVE-2026-81302
8.5JAL Information Technology Co., Ltd. · PALLET CONTROL
PALLET CONTROL products contain an incorrect default permission vulnerability, allowing a local attacker to execute arbitrary code with SYSTEM privileges.
Executive summary
A high-severity local privilege escalation vulnerability in JAL PALLET CONTROL products allows attackers to gain SYSTEM-level access to affected systems.
Vulnerability
This vulnerability is caused by incorrect default permissions (CWE-276), which can be exploited by an authenticated local user to escalate privileges to SYSTEM level. The attack vector is local (AV:L), meaning the actor must already have access to the target host to initiate the exploit.
Business impact
The ability for a local attacker to execute code with SYSTEM privileges poses a critical threat to the confidentiality, integrity, and availability of the affected system. With a CVSS score of 8.5, this high-severity flaw could allow an attacker to bypass security controls, install persistent malware, or move laterally within the network. Such an incident could result in total system compromise and significant operational downtime.
Remediation
Immediate Action: Update PALLET CONTROL to Ver. 6.3 Patch 6, or PalletControl and PalletControl Cloud to 10 Update 9 or later.
Proactive Monitoring: Audit local system logs for unauthorized account modifications or the execution of unexpected processes originating from service accounts.
Compensating Controls: Implement strict host-based access controls and ensure that only authorized personnel have local login capabilities to prevent unprivileged users from accessing the host environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high-severity impact of gaining SYSTEM-level privileges, organizations must prioritize applying the provided patches across all affected PALLET CONTROL environments. Failure to remediate this vulnerability leaves systems susceptible to full compromise by any local actor. Please coordinate with IT administrators to schedule the deployment of the required updates immediately.