CVE-2026-20468: Medium severity apusys vulnerability
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch AUTO00833804 - Compensating control
Mitigate local privilege escalation risk by preventing/limiting System-privileged code execution where feasible (e.g., restrict which processes/users can obtain or run with System privilege) while patch AUTO00833804 is applied.