CVE-2026-15430 is an improper access-control vulnerability in the IRP_MJ_WRITE command interface of the Wellbia XIGNCODE3 kernel driver, version 2026.6.1.192. The driver's module, caller, and request-authentication controls can reportedly be bypassed, exposing privileged command paths to a local unprivileged caller. Exposed operations include cross-process memory access, creation of handles to protected processes, process termination, and kernel-assisted code injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Rust workspace containing two local Windows exploit PoCs plus a shared credential-extraction library. The repository targets Wellbia XIGNCODE3 anti-cheat drivers: axhunter_v1 attacks xhunter1.sys v2023.12.7.78, and axhunter_v2 attacks xhunter2.sys v2026.6.1.192 (CVE-2026-15430). The shared crate axhunter-lsa implements driver-agnostic LSASS secret extraction by abstracting memory reads behind a MemReader trait, then walking remote PEB/LDR structures, locating lsasrv.dll and wdigest.dll patterns, extracting BCrypt 3DES key material, and decrypting LogonSessionList and WDigest entries. Exploit capabilities are substantial and clearly offensive. Both variants first bypass driver-specific authorization gates, then use opcode 785 to obtain a kernel-minted PROCESS_ALL_ACCESS handle to arbitrary processes, including protected processes. They use opcode 787 as a cross-process memory read primitive for LSASS dumping, opcode 800 to forcibly close handles in a target process for process termination/evasion, and remote-thread injection into winlogon.exe for local privilege escalation to SYSTEM. The v1 exploit bypasses a per-PID gate by issuing unauthenticated commands 777 and 775 to set required flags. The v2 exploit is more complex: it bypasses three authentication layers by mapping an embedded signed WBMF module, crafting a minimal WBCC blob, and chaining commands 777, 779, and 775 to satisfy the PID flag gate. Repository structure: root workspace manifest; axhunter-lsa shared library; axhunter_v1 standalone PoC with driver wrapper, process helpers, and CLI; axhunter_v2 standalone PoC split into protocol, session, WBMF mapping, dump, kill, and LPE modules. Entry points are axhunter_v1/src/main.rs and axhunter_v2/src/main.rs. No network C2 or remote endpoints are present; this is a purely local Windows post-exploitation toolkit focused on abusing vulnerable anti-cheat drivers for credential theft, process tampering, and SYSTEM shell access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.