Description
Improper authorization leads to Remote Code Execution via SocketIO interface.
Published: 2026-09-22
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Improper authorization on the Qualcomm Snapdragon Software Center’s SocketIO interface allows an attacker to execute arbitrary code with system privileges, completely compromising confidentiality, integrity, and availability. The flaw is a classic example of the weakness identified by CWE-285, Unauthorized access via improper authorization.

Affected Systems

The vulnerability affects Qualcomm, Inc.’s Snapdragon software. The data do not specify exact affected versions, so any installation of Snapdragon that includes the exposed SocketIO endpoint could be vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the absence of an EPSS score does not diminish the risk. The flaw is publicly documented but not listed in the CISA KEV catalog. It can be exploited over a network by an attacker with access to the SocketIO interface, providing an attitude for remote code execution without needing elevated privileges on the target system.

Generated by OpenCVE AI on September 22, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Qualcomm’s security patch that fixes the improper authorization in the Snapdragon Software Center’s SocketIO interface as soon as it is released.
  • If a patch is not yet available, block or restrict access to the SocketIO endpoint using firewall rules or network segmentation to limit exposure to trusted hosts.
  • Verify that all client connections to the SocketIO interface use proper authentication credentials and enforce role‑based access control in any custom authentication logic that may exist.

Generated by OpenCVE AI on September 22, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper authorization leads to Remote Code Execution via SocketIO interface.
Title Improper authorization in Qualcomm Software Center
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-22T10:15:28.212Z

Reserved: 2026-02-02T04:19:00.938Z

Link: CVE-2026-25254

cve-icon Vulnrichment

Updated: 2026-09-22T10:14:46.694Z

cve-icon NVD

Status : Received

Published: 2026-09-22T10:17:08.583

Modified: 2026-09-22T11:17:24.107

Link: CVE-2026-25254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T11:30:09Z

Weaknesses