cvefeed.io
Seagull Software BarTender Vulnerabilities Enable RCE and Privilege Escalation
Article Content
Seagull Software's BarTender has two critical vulnerabilities affecting versions 2010, 2016, 2019, and 2021. CVE-2026-25550 allows unauthenticated remote code execution via the .NET Remoting service on TCP port 7375, exposing sensitive data and enabling lateral movement. CVE-2026-25551 permits local privilege escalation for low-privileged users through insecure deserialization on the DataServiceSingleton endpoint. Both vulnerabilities stem from unsafe deserialization patterns and can lead to full system compromise. The issues were disclosed on June 4, 2026, and are currently unpatched, posing significant risks to affected systems. Organizations using these versions of BarTender are urged to assess their exposure and implement mitigations.
Key Points: • CVE-2026-25550 allows unauthenticated RCE on BarTender 2010, 2016, and 2019. • CVE-2026-25551 enables local privilege escalation on BarTender 2021 R1 through 12.0.1. • Both vulnerabilities are due to unsafe deserialization and are currently unpatched.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.