SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-20467

MEDIUM · CVSS 6 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

A vulnerability in apusys allows for local escalation of privilege due to a missing bounds check, enabling an attacker with System privileges to exploit the flaw without user interaction. Organizations using affected versions of apusys should prioritize applying the patch (AUTO00837766) to mitigate potential unauthorized access and control over system resources. This issue is particularly relevant for environments where sensitive operations are performed under System privileges.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20467
Severity
MEDIUM
CVSS
6
EPSS
0.12%

Original NVD Description

In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.