
AgostinoSturaro asked a question.
Is CVE-2026-4869 related to ISDEV-44981? Was this fixed in InstallShield 2026 R1? The lack of a date on posts about CVEs makes it hard to figure out this kind of information. It is also very difficult to understand what the patch files to download are.
Hi Agostino,
The issue has been fixed in InstallShield 2026 R1.
Please check and for any issues, please reach out to us at support@revenera.com with the errors and the screenshots. We will be happy to help you.
Regards,
Sunil.
Is CVE-2026-4869 related to ISDEV-44981, or are the two separate issues?
Thanks.
@AgostinoSturaro : You can find the details of the cve in below KB article
https://community.revenera.com/s/article/CVE-2026-4869-Potential-Privilege-Escalation-in-InstallShield-2025-R2-running-Setup-Prerequisites-from-an-insecure-directory.
You can find the hotfix for 2025R2 for this specific CVE in our product and license center
Is CVE-2026-4869 related to ISDEV-44981, or are the two separate issues?
https://docs.revenera.com/installshield/rn/Content/helplibrary/InstallShield_2026_R1_1.htm
That is not written in the article.
Thanks.
@AgostinoSturaro Both are different
ISDEV-44981 is related to - security vulnerability on standard user to execute actions that resulted into elevated privileges (SYSTEM-level access) --> The CVE for this issue is https://community.revenera.com/s/article/cve-2024-7562-privilege-escalation-vulnerability-in-created-msi-packages
CVE-2026-4869 --> Specific to executing prq execution from insecure directory (ISDEV-45022)
Did my reply solve the question? Click "ACCEPT AS SOLUTION" to help others find answers faster. Liked something? Click "KUDO".
If ISDEV-44981 is related CVE-2024-7562, which was fixed in InstallShield 2024 R1, why does it appear in the release notes for 2026 R1?
Is it a new variant of an that CVE?
If not, is CVE-2026-4869 actually fixed in InstallShield 2026 R1?
That is not clear from the release notes.
Thanks.
Could you please confirm where did you see this Is CVE-2026-4869 related to ISDEV-44981 ,
Please explain in detail what exactly you have confusion, If possible please share a screenshot.
The InstallShield 2026 R1 release notes do not mention any specific CVE, they only mention a security fix (ISDEV-44981).
https://community.revenera.com/s/article/CVE-2026-4869-Potential-Privilege-Escalation-in-InstallShield-2025-R2-running-Setup-Prerequisites-from-an-insecure-directory
This CVE-2026-4869 article does not mention InstallShield 2026 R1.
https://community.revenera.com/s/article/CVE-2026-4869-Potential-Privilege-Escalation-in-InstallShield-2025-R2-running-Setup-Prerequisites-from-an-insecure-directory
That's why I asked if CVE-2026-4869 and ISDEV-44981 are the same, to understand if the CVE-2026-4869 was fixed in InstallShield 2026 R1.
Moreover, what is the name and hash of the patch file for InstallShield 2025 R2?
It is not clear from the download page.
Thanks.
https://community.flexera.com/s/article/CVE-2026-4869-Potential-Privilege-Escalation-in-InstallShield-2025-R2-running-Setup-Prerequisites-from-an-insecure-directory
ISDEV-45022 --> CVE-2026-4869--> Fixed in IS2026R1,
https://community.revenera.com/s/article/cve-2024-7562-privilege-escalation-vulnerability-in-created-msi-packages
This CVE is initally reported for IS2023R2, with CVE-2024-7562
we have another sceurity issue(ISDEV-44981) reported over the same IS2023R2 hotfix with same CVE which is fixed over the same CVE-2024-7562, It's fixed in IS2026R1.
Please test it, if you still face any issue with related to the work order and CVE, you can raise a support ticket.
Thank you for your clarifications.
Does the file "InstallShield_2025_R2_Security_Patch.exe" (16395112 bytes) fix both issues, or just CVE-2026-4869?