SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-0187

MEDIUM · CVSS 6.7 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A logic error in the gsa_sw_pk_hash_compare function of image-auth-srv.c may allow local users to escalate their privileges to System level without requiring user interaction. This vulnerability poses a significant risk to systems where the affected code is deployed, making it crucial for organizations using this software to prioritize remediation efforts to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-0187
Severity
MEDIUM
CVSS
6.7
EPSS
0.12%

Original NVD Description

In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.