AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-34175

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows an unprivileged adversary to escalate privileges within the Hardware-Aware-Automated-MachineLearning application prior to version 45cd723, due to an uncontrolled search path in user applications. This could lead to significant impacts on system confidentiality, integrity, and availability, particularly through local access with minimal attack complexity and passive user interaction. Organizations using this software should prioritize remediation to mitigate potential risks associated with privilege escalation.

CVE
CVE-2026-34175
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%

Original NVD Description

Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.