Description
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Published: 2026-07-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation flaw exists in the /etc/init.d/user-applications init script. The flaw enables a low-privileged local user to execute arbitrary system commands with root privileges, providing full control over the affected device. This vulnerability is a classic example of CWE-78, where unsanitized input is passed to the shell for execution.

Affected Systems

The product family impacted is Phoenix Contact’s CHARX SEC line, specifically the SEC–3000, SEC–3050, SEC–3100 and SEC–3150 models. No specific firmware or software version details were supplied, so the entire family is considered at risk until further information is released.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity for unauthorized privilege escalation. The EPSS score is under 1%, suggesting that while the risk to confidentiality, integrity, and availability is severe, the likelihood of exploitation at this time is low. The flaw is not listed in CISA’s KEV, and the attack vector is local: a compromised or already logged-in low-privileged user can trigger the init script to elevate to root. Mitigation therefore hinges on local preventive measures or an official patch from Phoenix Contact.

Generated by OpenCVE AI on August 4, 2026 at 11:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Be sure to install the official firmware or patch provided by Phoenix Contact when it becomes available, as it will remove the vulnerable init script or sanitize its inputs.
  • Until a patch is issued, disable the user-applications init script or delete the executable file to prevent execution with root privileges.
  • Verify that local user accounts do not have unnecessary sudo or root-equivalent privileges, and ensure that any web interface serving application files enforces strict authentication and input validation to prevent command injection attacks.

Generated by OpenCVE AI on August 4, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Title Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-78
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-31T22:47:27.002Z

Reserved: 2026-05-05T10:48:08.227Z

Link: CVE-2026-44106

cve-icon Vulnrichment

Updated: 2026-07-31T22:47:23.281Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:59.027

Modified: 2026-07-31T23:17:24.103

Link: CVE-2026-44106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:00:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')