CVE-2026-8920: ASUS Aura Wallpaper Service

High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Aura Wallpaper Service: from v2.1.8.0, up to and including v2.1.15.0

Published 2026-07-15. Last modified 2026-07-15.