SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-4018

MEDIUM · CVSS 6.4 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A TOCTOU race condition vulnerability in the TraceEvent() system call of the QNX Neutrino kernel can be exploited by local attackers with the PROCMGR_AID_TRACE capability, potentially leading to information disclosure, data tampering, or system crashes. Organizations using QNX Neutrino should prioritize patching this vulnerability to mitigate risks associated with local privilege escalation and system integrity.

CVE
CVE-2026-4018
Severity
MEDIUM
CVSS
6.4
EPSS
0.09%

Original NVD Description

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.