CVE-2020-26886: High severity softaculous vulnerability
Published Mar 18, 2021
·Updated
Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data Stores. This leads to privilege escalation on the local host.
Affected Software
1 affected component
Softaculous Softaculous<5.5.7
Event History
Mar 18, 2021
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26886?
CVE-2020-26886 has been classified as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2020-26886?
To mitigate CVE-2020-26886, update Softaculous to version 5.5.7 or later.
3
What can attackers achieve by exploiting CVE-2020-26886?
Exploiting CVE-2020-26886 allows attackers to execute arbitrary code on the affected system, resulting in privilege escalation.
4
Which versions of Softaculous are affected by CVE-2020-26886?
CVE-2020-26886 affects Softaculous versions prior to 5.5.7.
5
Is there a workaround for CVE-2020-26886 if I can't update?
There are no known effective workarounds for CVE-2020-26886; updating is the recommended solution.