Vulnerability Description
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.
Related Weaknesses (CWE)
References
- https://fluidattacks.com/es/advisories/soad
- https://xvpn.io/
- https://xvpn.io/download/vpn-mac
- https://xvpn.io/resources/statement-local-privilege-escalation-vulnerability
- https://fluidattacks.com/es/advisories/soad
FAQ
What is CVE-2026-2638?
CVE-2026-2638 is a documented vulnerability. A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve pri...
How severe is CVE-2026-2638?
CVSS scoring is not yet available for CVE-2026-2638. Check NVD for updates.
Is there a patch for CVE-2026-2638?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.