Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104018— VxWorks 7 improper privilege management

Quick assessment

Affected
Wind River Systems Inc VxWorks 7
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wind River VxWorks 7 的命令 shell 中存在一个不当的权限管理漏洞(CWE-269),该漏洞出现在配置了按用户执行命令权限控制的场景中。在某些 shell 操作下,某些命令可能绕过通常应用的权限检查而被执行,从而使拥有有限权限的已认证用户能够运行其未被授权执行的命令。成功利用该漏洞可能导致权限提升,进而影响受影响设备的机密性、完整性和可用性。该问题影响 VxWorks 7 26.09 之前的所有版本,并已在 26.09 版本中修复。

CVSS 8.8 · High EPSS 0.64% · P49

Affected Version Matrix 1

VendorProduct Version RangeStatus
Wind River Systems Inc VxWorks 7 VxWorks 7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104018

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
VxWorks 7 improper privilege management
Source: CVE Program / CVE List V5
Vulnerability Description
An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device. The issue affects all versions of VxWorks 7 prior to 26.09.  It has been fixed in 26.09.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Wind River Systems Inc VxWorks 7 VxWorks 7 -

II. Public POCs for CVE-2026-104018

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104018

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-104018 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104018

No comments yet


Leave a comment