CVE-2026-9854CWE-303
CVE-2026-9854
published September 3, 2026
What it is
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
The record
Technical detail
- CVSS
- 8.5 · NONE
- CVSS v4.0
- 8.5 · CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00122 · 2.3th percentile
- Weakness
- CWE-303 · Incorrect Implementation of Authentication Algorithm
- Published
- 2026-09-03T17:06Z
References (1)
EPSS history
Timeline