Description
Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation.

This issue affects GateManager: 11.5;0, 11.4.625515072:0.



Fixed in Version 11.6 or 11.4.626194074 and above
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An improper handling of insufficient permissions or privileges in Secomea GateManager exposes users with lower privileges to gain elevated access, resulting in unauthorized configuration changes or system control. The flaw is a classic privilege escalation weakness, identified as CWE-280, allowing an attacker to ascend hierarchies without legitimate authorization.

Affected Systems

Secomea GateManager versions 11.5 and 11.4.625515072 are vulnerable. The vulnerability is fixed in releases 11.6 and 11.4.626194074 and later. Devices running older revisions must be updated to avoid exploitation.

Risk and Exploitability

The CVSS rating of 6.5 indicates a moderate severity. EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely, exploitation requires initial access to the GateManager interface with an account that has limited permissions. The attacker can then leverage the permission bypass to obtain higher privileges, potentially compromising the entire system. No public exploit is known, but the moderate severity warrants prompt remediation.

Generated by OpenCVE AI on September 17, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GateManager to version 11.6 or 11.4.626194074 and above.
  • Restrict non‑privileged users from accessing configuration interfaces that may trigger the privilege escalation until the upgrade is applied.
  • Audit account privileges and remove any unnecessary elevated permissions to reduce the attack surface.

Generated by OpenCVE AI on September 17, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Permission Handling in GateManager Allows Privilege Escalation

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Improper Permission Handling in GateManager Allows Privilege Escalation

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Secomea
Secomea gatemanager
Vendors & Products Secomea
Secomea gatemanager

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above
Weaknesses CWE-280
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Secomea Gatemanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Secomea

Published:

Updated: 2026-09-15T12:20:46.282Z

Reserved: 2026-02-02T12:07:49.500Z

Link: CVE-2026-1759

cve-icon Vulnrichment

Updated: 2026-09-15T12:20:43.344Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T11:17:08.660

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-1759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges