CVE-2026-15430: Wellbia XIGNCODE3

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.

Affected products

  • Wellbia XIGNCODE3: version 2026.6.1.192 only

Published 2026-08-03. Last modified 2026-08-03.