---
id: CVE-2025-59887
title: >-
  Improper authentication of library files in the Eaton UPS Companion software
  installer could lead to arbitrary code execution of an attacker with the
  access to the software package
summary: >-
  Improper authentication of library files in the Eaton UPS Companion software
  installer could lead to arbitrary code execution of an attacker with the
  access to the software package.  This security issue has been fixed in the
  latest versi…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: eaton
product: ups_companion
affected:
  - ups_companion < 3.0
patched:
  - ups_companion 3.0
published: '2025-12-26'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:10:00.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59887'
references:
  - url: >-
      https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1026.pdf
    label: CybersecurityCOE@eaton.com
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.16373
ingestedAt: '2026-10-07T13:31:04.576Z'
---

## Overview

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package.  This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

## Affected

- `ups_companion < 3.0`

## Remediation

Upgrade past the affected range:

- `ups_companion 3.0`
