CVE-2026-4416

HIGH WAF: Medium
CVSS 7.8 Published: 2026-03-30
CWE-502

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

WAF Coverage Analysis

Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack

Affected Software

VendorProductVersion
gigabyteperformance_libraryup to 25.12.31.01

References

Back to CVE Database