A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
|
History
Thu, 30 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
|
| Vendors & Products |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
Thu, 30 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| Title | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script | |
| First Time appeared |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2026-07-30T06:48:19.608Z
Updated: 2026-07-30T12:55:41.446Z
Reserved: 2026-05-05T10:48:08.226Z
Link: CVE-2026-44093
No data.
No data.
No data.