cvefeed.io
Seagull Software BarTender Vulnerabilities Enable RCE and Privilege Escalation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Seagull Software's BarTender has two critical vulnerabilities affecting versions 2010, 2016, 2019, and 2021. CVE-2026-25550 allows unauthenticated remote code execution via the .NET Remoting service on TCP port 7375, exposing sensitive data and enabling lateral movement. CVE-2026-25551 permits local privilege escalation for low-privileged users through insecure deserialization on the DataServiceSingleton endpoint. Both vulnerabilities stem from unsafe deserialization patterns and can lead to full system compromise. The issues were disclosed on June 4, 2026, and are currently unpatched, posing significant risks to affected systems. Organizations using these versions of BarTender are urged to assess their exposure and implement mitigations.
Key Points: • CVE-2026-25550 allows unauthenticated RCE on BarTender 2010, 2016, and 2019. • CVE-2026-25551 enables local privilege escalation on BarTender 2021 R1 through 12.0.1. • Both vulnerabilities are due to unsafe deserialization and are currently unpatched.