OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102117

HIGH · CVSS 7.2 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Authenticated System Administrators with access to the remote-support capability can exploit a vulnerability to redirect outbound support connections to arbitrary destinations, allowing execution of operating system commands on the affected system. This could lead to remote code execution with the privileges of a local service account, posing a significant risk to system integrity and security. Organizations utilizing the remote-support feature should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102117
Severity
HIGH
CVSS
7.2
EPSS
0.42%

Original NVD Description

On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.