CVE-2026-67609: Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration

Published Aug 3, 2026
·
Updated

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.

Affected Software

1 affected component
Telenia TVox>=26.x<=26.5.3, >24.x<24.9.21

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Telenia Software TVox to a version that resolves this vulnerability.

    Fixed in 26.5.3
  2. Upgrade

    Upgrade Telenia Software TVox to a version that resolves this vulnerability.

    Fixed in 24.9.21
  3. Configuration

    Edit /etc/sudoers.d/telenia to eliminate the insecure sudoers rule that grants the apache user NOPASSWD execution of /bin/nice, which is leveraged to execute arbitrary commands as root.

    Telenia TVox (sudo configuration) /etc/sudoers.d/telenia rule for apache NOPASSWD /bin/nice = Remove NOPASSWD authorization for /bin/nice for user apache (or otherwise ensure apache cannot execute /bin/nice via sudo without password)

Event History

Aug 3, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-67609?

The severity of CVE-2026-67609 is high with a CVSS score of 7.8.

2

How do I fix CVE-2026-67609?

To fix CVE-2026-67609, review and update the sudoers configuration to restrict permissions for the apache account.

3

What systems are affected by CVE-2026-67609?

CVE-2026-67609 affects Telenia Software TVox versions 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions.

4

What type of vulnerability is CVE-2026-67609?

CVE-2026-67609 is a privilege escalation vulnerability that allows attackers to execute commands as root.

5

What access do attackers need to exploit CVE-2026-67609?

Attackers need access to the apache account to exploit CVE-2026-67609.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203