Unrated severityNVD Advisory· Published Jan 15, 2026· Updated Jan 16, 2026
Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
CVE-2020-36928
Description
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.
Affected products
2- Brother/Brother BRAgentv5Range: 1.38
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/50010mitreexploit
- www.vulncheck.com/advisories/brother-bragent-wbaagentclient-unquoted-service-pathmitrethird-party-advisory
- help.brother-usa.com/app/answers/detail/a_id/174732/~/what-is-bragent%3Fmitreproduct
News mentions
0No linked articles in our index yet.