PatchSiren

Bizerba SE & Co. KG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bizerba SE & Co. KG CVE published 2026-07-20

CVE-2026-16247

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T12:17:56.230Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects _connect.BRAIN versions prior to 5.06, where the application LogPathConfig.exe is executed during setup, deleting and replacing existing permissions on %ProgramData%, grant [truncated]

HIGH Bizerba SE & Co. KG CVE published 2026-07-20

CVE-2026-16246

A high-severity vulnerability was discovered in BRAIN2 versions prior to 3.09. During setup, the application LogPathConfig.exe is executed, granting the Windows group Everyone full control over %ProgramData% instead of restricting it to %ProgramData%<br> <br>Bizerba ScriptService still executes this tool but is being deprecated and will no longer be included starting with BRAIN2 version 3.11. This vulnera [truncated]