CVE-2026-104018High· 8.8▾ TwilightAn improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the p…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device. The issue affects all versions of VxWorks 7 prior to 26.09. It has been fixed in 26.09.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102005Medium· 5.5Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools…
CVE-2026-102006Medium· 5.5In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application
CVE-2026-102004High· 7.8Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem
CVE-2026-97686Medium· 5.5Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.