CVE-2026-28625: Security vulnerability
Published Oct 5, 2026
·Updated
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Oct 5, 2026
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
Exploitation is local and can result in escalation of privilege. The attacker does not need any additional execution privileges, and no user interaction is required.