PatchSiren

NortheBridge CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NortheBridge CVE published 2026-08-13

CVE-2026-50544

A latent vulnerability exists in NortheBridge/luminalshine, a Sunshine-compatible game stream host for Moonlight, prior to version 26.05.0-rc4. The issue arises from a file created by the SYSTEM service at `C:/ProgramData/LuminalShine/config/apps.json`, which is readable and executable by BUILTIN/Users due to Windows' default C:/ProgramData inheritance. However, the file is not writable by BUILTIN/Users. [truncated]