Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.

Project Subscriptions

Vendors Products
Forcepoint Subscribe
Ngfw Engine Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to versions 6.10.20, 7.1.11, 7.2.5 and 7.3.1.


Workaround

No workaround given by the vendor.

History

Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Forcepoint
Forcepoint ngfw Engine
Vendors & Products Forcepoint
Forcepoint ngfw Engine

Wed, 11 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
Description Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.
Title Local Privilege Escalation in NGFW Engine
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2026-03-11T16:10:28.588Z

Reserved: 2025-11-04T10:07:46.152Z

Link: CVE-2025-12690

cve-icon Vulnrichment

Updated: 2026-03-11T16:10:25.394Z

cve-icon NVD

Status : Received

Published: 2026-03-11T16:16:18.233

Modified: 2026-03-11T16:16:18.233

Link: CVE-2025-12690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-12T10:05:41Z

Weaknesses