CVE-2026-59683: CALCPROGRAMMER1 Openrgb

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context).

Affected products

Published 2026-08-26. Last modified 2026-09-01.