SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-50602

HIGH · CVSS 8.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the Planet9 background service due to improper file permissions on its executable, allowing authenticated local users to modify or replace it. This could lead to the execution of arbitrary code with SYSTEM privileges, posing a significant security risk. Organizations using Planet9 should prioritize remediation to prevent potential exploitation by local users.

CVE
CVE-2026-50602
Severity
HIGH
CVSS
8.5
EPSS
0.11%

Original NVD Description

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.