CVE-2026-8920: ASUS Aura Wallpaper Service
High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Affected products
- ASUS Aura Wallpaper Service: from v2.1.8.0, up to and including v2.1.15.0
Published 2026-07-15. Last modified 2026-07-15.