OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-55270

HIGH · CVSS 7.8 EPSS 0.07% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A permission bypass vulnerability exists in the dialInternal function, allowing local escalation of privileges without requiring additional execution rights or user interaction. This issue poses a significant risk to systems where the affected function is utilized, making it critical for organizations using these systems to prioritize remediation efforts to prevent unauthorized access and potential exploitation. Security teams should assess their environments for the presence of this vulnerability and implement necessary mitigations promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55270
Severity
HIGH
CVSS
7.8
EPSS
0.07%

Original NVD Description

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.