MEDIUM
NortheBridge
CVE published 2026-08-13
CVE-2026-50544
A latent vulnerability exists in NortheBridge/luminalshine, a Sunshine-compatible game stream host for Moonlight, prior to version 26.05.0-rc4. The issue arises from a file created by the SYSTEM service at `C:/ProgramData/LuminalShine/config/apps.json`, which is readable and executable by BUILTIN/Users due to Windows' default C:/ProgramData inheritance. However, the file is not writable by BUILTIN/Users. [truncated]