CVE-2026-23648

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these binaries to execute arbitrary commands with root privileges, enabling local privilege escalation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-17 17:21

Updated : 2026-02-18 17:52


NVD link : CVE-2026-23648

Mitre link : CVE-2026-23648

CVE.ORG link : CVE-2026-23648


JSON object : View

Products Affected

No product.

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource