CVE-2026-27668: High severity RUGGEDCOM RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) vulnerability
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27668?
CVE-2026-27668 has been rated as a high-severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2026-27668?
To mitigate CVE-2026-27668, upgrade RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) to version 5.8 or later.
Who is affected by CVE-2026-27668?
Any authenticated user with User Administrator privileges in versions of RUGGEDCOM CROSSBOW SAM-P earlier than 5.8 is affected.
What can an attacker do with CVE-2026-27668?
An attacker exploiting CVE-2026-27668 could escalate their privileges and gain unauthorized access to administrative functionalities.
When was CVE-2026-27668 disclosed?
CVE-2026-27668 was disclosed in the context of a security advisory by Siemens.