CVE-2026-20497: Medium severity GenieZone geniezone vulnerability
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10965550 / ALPS11393405
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20497?
The severity of CVE-2026-20497 is classified as medium, with a CVSS score of 6.
How do I fix CVE-2026-20497?
To fix CVE-2026-20497, apply the available patches identified as ALPS10965550 or ALPS11393405.
What type of vulnerability is CVE-2026-20497?
CVE-2026-20497 is an out of bounds write vulnerability that can lead to local escalation of privilege.
Does CVE-2026-20497 require user interaction for exploitation?
No, CVE-2026-20497 does not require user interaction for exploitation.
What software is affected by CVE-2026-20497?
The vulnerability CVE-2026-20497 affects GenieZone.