Seagull Software BarTender Vulnerabilities Enable RCE and Privilege Escalation

Seagull Software BarTender Vulnerabilities Enable RCE and Privilege Escalation

First seen 4 Jun 2026, 23:06 UTC Mallory.Aicvefeed.iowww.vulncheck.com 88% similarity 71.0

Article Content

Browse articles
ThreatCluster

Seagull Software's BarTender has two critical vulnerabilities affecting versions 2010, 2016, 2019, and 2021. CVE-2026-25550 allows unauthenticated remote code execution via the .NET Remoting service on TCP port 7375, exposing sensitive data and enabling lateral movement. CVE-2026-25551 permits local privilege escalation for low-privileged users through insecure deserialization on the DataServiceSingleton endpoint. Both vulnerabilities stem from unsafe deserialization patterns and can lead to full system compromise. The issues were disclosed on June 4, 2026, and are currently unpatched, posing significant risks to affected systems. Organizations using these versions of BarTender are urged to assess their exposure and implement mitigations.

Key Points: • CVE-2026-25550 allows unauthenticated RCE on BarTender 2010, 2016, and 2019. • CVE-2026-25551 enables local privilege escalation on BarTender 2021 R1 through 12.0.1. • Both vulnerabilities are due to unsafe deserialization and are currently unpatched.

ThreatCluster AI

Timeline

2026-06-04
CVE-2026-25550 published
Unauthenticated RCE vulnerability disclosed for BarTender 2010, 2016, and 2019 via .NET Remoting service.
cvefeed.io
2026-06-04
CVE-2026-25551 published
Insecure deserialization vulnerability disclosed for BarTender 2021 R1 through 12.0.1, allowing local privilege escalation.
cvefeed.io
2026-06-04
Vulnerabilities reported
Seagull Software BarTender vulnerabilities reported, affecting multiple versions and enabling serious security risks.
Mallory.Ai

Community

Browse all →