Vulnerability Description
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/thesmartshadow/ed96e2a88643c34a247c9b7cf9e311be
- https://github.com/ncopa/su-exec
- https://github.com/ncopa/su-exec/blob/89c016e6e08749d583efdeda04b9f73e1218e253/s
- https://www.vulncheck.com/advisories/su-exec-through-0.3-privilege-escalation-vi
- https://gist.github.com/thesmartshadow/ed96e2a88643c34a247c9b7cf9e311be
FAQ
What is CVE-2026-82457?
CVE-2026-82457 is a vulnerability with a CVSS score of 7.8 (HIGH). su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can suppl...
How severe is CVE-2026-82457?
CVE-2026-82457 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82457?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.