CVE-2026-24063Disclosure

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper gets instructed to execute this script. When the bash script is manipulated by an attacker this scenario will lead to privilege escalation.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3PoC Mentioned / Linked · 2026-03-18: 2Exploit Tool / Code · 2026-03-18: 1Technical Details · 2026-03-18: 303-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-24063 - High When a plugin is installed using the Arturia Software Center (MacOS), it also installs an http://uninstall.sh bash script in a root owned path. This script is written to disk with the file permissio... https://www.thehackerwire.com/vulnerability/CVE-2026-24063/ https://t.co/DdwEa362Fx

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑24063) in Arturia’s macOS Software Center involving an improperly permissioned uninstall script, but provides no active exploitation, patch, or exploit code details.

    0001031
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24063 When a plugin is installed using the Arturia Software Center (MacOS), it also installs an http://uninstall.sh bash script in a root owned path. This script is written to dis… https://www.cve.org/CVERecord?id=CVE-2026-24063

    Post summary

    The CVE concerns the Arturia Software Center installing a root‑owned uninstall script on macOS, with no mention of active exploitation or patch availability. The referenced script suggests a potential proof‑of‑concept exists.

    00000110
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-24063 - World-writable uninstall script executed as root in Arturia Software Center Intel Report: https://ift.tt/JNtDoYc

    Post summary

    The alert announces CVE-2026-24063, describing a root‑execution risk from a world‑writable uninstall script in Arturia Software Center, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000031
    335 followersView on X

Explore more