Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ncopa
Ncopa su-exec |
|
| Vendors & Products |
Ncopa
Ncopa su-exec |
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts. | |
| Title | su-exec through 0.3 Privilege Escalation via Numeric User ID | |
| Weaknesses | CWE-681 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T02:10:51.942Z
Reserved: 2026-08-29T13:23:00.303Z
Link: CVE-2026-82457
Updated: 2026-09-01T02:10:47.591Z
Status : Received
Published: 2026-08-29T14:16:38.910
Modified: 2026-09-01T03:16:52.223
Link: CVE-2026-82457
No data.
OpenCVE Enrichment
Updated: 2026-08-31T11:19:42Z
