CVE-2026-28700: Medium severity EquiTriton vulnerability
Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28700?
CVE-2026-28700 has a risk rating of 46, indicating a moderate level of severity.
How do I fix CVE-2026-28700?
To mitigate CVE-2026-28700, update EquiTriton to the latest version released after f5ddbb5.
What applications are affected by CVE-2026-28700?
CVE-2026-28700 affects user applications within EquiTriton software version prior to f5ddbb5.
What type of attack does CVE-2026-28700 allow?
CVE-2026-28700 allows an escalation of privilege through an uncontrolled search path vulnerability.
Who is at risk from CVE-2026-28700?
Unprivileged software adversaries targeting users of EquiTriton prior to version f5ddbb5 are at risk from CVE-2026-28700.