Insecure DLL loading in PowerAttendant Standard Edition - CVE-2026-5397
Published: April 20, 2026
PowerAttendant Standard Edition
Detailed vulnerability description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner within the UPS (Uninterruptible Power Supply) management application. A local user can place a specially crafted .dll file and execute arbitrary code on the system with elevated privileges.