AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-28700

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Certain versions of F5's EquiTriton are vulnerable to an uncontrolled search path issue, which could allow an unprivileged adversary to escalate privileges under specific conditions. This vulnerability poses significant risks to the confidentiality, integrity, and availability of the system, making it critical for organizations using affected versions to prioritize remediation. Users with local access should be particularly vigilant, as the attack can be executed with low complexity and minimal user interaction.

CVE
CVE-2026-28700
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
F5

Original NVD Description

Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.