CVE-2026-16247: CWE-276 Incorrect default permissions in Bizerba SE & Co. KG _connect.BRAIN
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool.
AI Analysis
Technical Summary
The vulnerability CVE-2026-16247 in Bizerba SE & Co. KG's _connect.BRAIN affects versions prior to 5.06. During setup, the LogPathConfig.exe application deletes existing permissions on the %ProgramData% directory and replaces them with permissions granting the Windows group Everyone full control. This is an incorrect default permission setting (CWE-276) that could lead to unauthorized access to data stored under %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. The issue is resolved starting with version 5.06, where the setup no longer executes this tool.
Potential Impact
The vulnerability allows unauthorized users with local access to gain full control over the %ProgramData% directory, potentially leading to confidentiality, integrity, and availability impacts on data related to _connect.BRAIN. The CVSS 3.1 score is 7.3 (high), reflecting high impact on confidentiality and integrity, and low attack vector complexity requiring local privileges.
Mitigation Recommendations
Upgrade to _connect.BRAIN version 5.06 or later, as these versions no longer execute the LogPathConfig.exe tool during setup and thus do not apply the incorrect permissions. Patch status is not explicitly confirmed in vendor advisory content, but the description states the issue is resolved starting with 5.06. Until upgrade, restrict local access to affected systems to mitigate risk.
CVE-2026-16247: CWE-276 Incorrect default permissions in Bizerba SE & Co. KG _connect.BRAIN
Description
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool.
CVSS v3.1
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-16247 in Bizerba SE & Co. KG's _connect.BRAIN affects versions prior to 5.06. During setup, the LogPathConfig.exe application deletes existing permissions on the %ProgramData% directory and replaces them with permissions granting the Windows group Everyone full control. This is an incorrect default permission setting (CWE-276) that could lead to unauthorized access to data stored under %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. The issue is resolved starting with version 5.06, where the setup no longer executes this tool.
Potential Impact
The vulnerability allows unauthorized users with local access to gain full control over the %ProgramData% directory, potentially leading to confidentiality, integrity, and availability impacts on data related to _connect.BRAIN. The CVSS 3.1 score is 7.3 (high), reflecting high impact on confidentiality and integrity, and low attack vector complexity requiring local privileges.
Mitigation Recommendations
Upgrade to _connect.BRAIN version 5.06 or later, as these versions no longer execute the LogPathConfig.exe tool during setup and thus do not apply the incorrect permissions. Patch status is not explicitly confirmed in vendor advisory content, but the description states the issue is resolved starting with 5.06. Until upgrade, restrict local access to affected systems to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bizerba
- Date Reserved
- 2026-07-20T07:04:24.445Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e143c2a4a8d598907deab
Added to database: 07/20/2026, 12:27:40 UTC
Last enriched: 07/20/2026, 12:42:00 UTC
Last updated: 07/20/2026, 21:14:55 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.