CVE-2026-102117

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.2
HIGH

Description

On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.

Published
September 30, 2026 9:16 PM
Last Modified
September 30, 2026 9:16 PM
Source
9119a7d8-5eab-497f-8521-727c672e3725

Weaknesses (CWE)

CWE-807 CWE-940

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.