A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
|
History
Thu, 30 Jul 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
|
| Vendors & Products |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
Thu, 30 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | |
| Title | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file | |
| First Time appeared |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2026-07-30T06:52:58.069Z
Updated: 2026-07-30T06:52:58.069Z
Reserved: 2026-05-05T10:48:08.227Z
Link: CVE-2026-44106
No data.
No data.
No data.