---
id: CVE-2026-2998
title: >-
  ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing
  authenticated local attackers to place a crafted DLL file in the same
  directory as the program, thereby executing arbitrary code.
summary: >-
  ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing
  authenticated local attackers to place a crafted DLL file in the same
  directory as the program, thereby executing arbitrary code.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
published: '2026-02-23'
updated: '2026-07-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2998'
references:
  - url: 'https://www.chtsecurity.com/news/3ba23045-da8a-4925-b476-967234a0abba'
    label: twcert@cert.org.tw
  - url: 'https://www.chtsecurity.com/news/95b1c87c-7649-4f9d-bbd6-b69c16b59cea'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/en/cp-139-10723-14549-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10722-db7cb-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
epss: 0.00119
epssPercentile: 0.01989
ingestedAt: '2026-07-28T08:33:00.859Z'
---

## Overview

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
