OpenRGB 1.0 has been released as a GPLv2-licensed, cross-platform C/C++ application for managing RGB hardware without vendor-specific software. The release supports 2,551 devices across motherboards, memory, GPUs, peripherals, controllers, and smart-lighting products; it also adds HID hot-plug handling, JSON-based profiles, and SDK/protocol improvements, while replacing the Windows WinRing0 driver dependency with Pawnio.
The release addresses CVE-2026-59682 and CVE-2026-59683 in OpenRGB protocol handling. Crafted SAVE_PROFILE requests could exploit path traversal to write files outside intended locations, while combined UPDATEMODE and SAVE_PROFILE commands could overwrite arbitrary files if OpenRGB runs with root privileges. openSUSE packages already include fixes; organizations should update OpenRGB deployments and avoid running its SDK server with elevated privileges unless necessary.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Updated openSUSE OpenRGB packages incorporated fixes for CVE-2026-59682, which permits path traversal and arbitrary file writes through SAVE_PROFILE, and CVE-2026-59683, which can enable arbitrary file overwrites via UPDATEMODE and SAVE_PROFILE when OpenRGB runs with root privileges.
The OpenRGB project released version 1.0, a GPLv2-licensed cross-platform RGB-device control application for Linux, macOS, and Windows. The release adds support for 2,551 devices and introduces changes including Pawnio on Windows, HID hot-plug handling, JSON profiles, and SDK improvements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.