CVE-2026-30332
the affected product
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.
- CVSS
- 7.5
- EPSS
- 0.17% 6.51% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.03