VU#330121: IDrive for Windows contains local privilege escalation vulnerability

2026-03-24T20:52:12Zd489c44db5cce726234838c222fa6fadc49af9e7d30e40a40213c00f83879a42
CRLFCVE-2026-1995GoHarborHarborHarbor12345IDriveLibreChatNT AUTHORITY\\SYSTEMNode.jsObject.prototypeRAG APISGLangaudit log tamperingcontainer registrydefault credentialsgraphql-upload-minimalid_service.exelocal privilege escalationlog injectionpickle deserializationprototype pollutionprototype pollution (processRequest)supply-chainunauthenticated RCEunsafe deserialization

What happened

Collection of CERT/CC vulnerability notes covering multiple products: (1) IDrive for Windows (<=7.0.0.63) has a local privilege escalation (CVE-2026-1995) where id_service.exe reads writable ProgramData files and can be induced to execute arbitrary binaries as NT AUTHORITY\SYSTEM; (2) GoHarbor/Harbor ships a default admin password (Harbor12345) that is not forced to change, enabling remote administrative compromise and supply-chain risks; (3) LibreChat RAG API v0.7.0 has a log-injection (CRLF) weakness allowing authenticated attackers to forge or manipulate audit logs and potentially enable X‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
d489c44db5cce726234838c222fa6fadc49af9e7d30e40a40213c00f83879a42
Enrichment time
2026-03-24T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.