---
id: CVE-2026-67609
title: >-
  Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior
  24.x versions, contain a privilege escalation vulnerability that allows
  attackers with access to the apache account to execute arbitrary commands as
  root by expl…
summary: >-
  Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior
  24.x versions, contain a privilege escalation vulnerability that allows
  attackers with access to the apache account to execute arbitrary commands as
  root by expl…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-250
published: '2026-08-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:40:01.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67609'
references:
  - url: 'https://karmainsecurity.com/KIS-2026-16'
    label: disclosure@vulncheck.com
  - url: 'https://www.teleniasoftware.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/telenia-tvox-privilege-escalation-via-insecure-sudoers-configuration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00141
epssPercentile: 0.03797
ingestedAt: '2026-09-09T21:22:45.521Z'
---

## Overview

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
