2026-07-28 14:1CVE-2026-8164TR-CERT
PUBLISHED5.2CWE-427

Search Order Hijacking in ArkSigner's ArkSigner Desktop Client

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.

This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.

Problem type

Affected products

ArkSigner Software and Hardware Industry and Trade Inc.

ArkSigner Desktop Client

<= 17062026 - AFFECTED

References

GitHub Security Advisories

GHSA-8gx5-vcv7-jq3w

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and...

https://github.com/advisories/GHSA-8gx5-vcv7-jq3w

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.

This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-8164
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-8164",
    "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
    "assignerShortName": "TR-CERT",
    "dateUpdated": "2026-07-28T14:01:02.028Z",
    "dateReserved": "2026-05-08T11:29:48.099Z",
    "datePublished": "2026-07-28T14:01:02.028Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "shortName": "TR-CERT",
        "dateUpdated": "2026-07-28T14:01:02.028Z"
      },
      "datePublic": "2026-07-28T13:38:00.000Z",
      "title": "Search Order Hijacking in ArkSigner's ArkSigner Desktop Client",
      "descriptions": [
        {
          "lang": "en",
          "value": "Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.\n\nThis issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking.<p>This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "ArkSigner Software and Hardware Industry and Trade Inc.",
          "product": "ArkSigner Desktop Client",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "v2.2.16.10",
              "status": "affected",
              "versionType": "custom",
              "lessThanOrEqual": "17062026"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-427 Uncontrolled Search Path Element",
              "cweId": "CWE-427",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0665",
          "tags": [
            "government-resource"
          ]
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-471",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-471 Search Order Hijacking"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 7.3,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Alperen KESKİN",
          "type": "finder"
        }
      ]
    }
  }
}