CVE-2025-59887
Published: 26 December 2025
Summary
CVE-2025-59887 is a high-severity Uncontrolled Search Path Element (CWE-427) vulnerability in Eaton Ups Companion. Its CVSS base score is 8.6 (High).
Operationally, ranked at the 17.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-205429
Vulnerability details
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC…
more
which is available on the Eaton download center.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.