Description
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.
Published: 2026-08-26
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient input validation in Admin By Request (ABR) allows a low-privileged user to inject malicious entries into the sudoers file, giving the attacker persistent root access that remains effective after the ABR session ends. The flaw leads to unauthorized elevation of privileges, enabling the attacker to execute commands with superuser rights and bypass normal security controls.

Affected Systems

The vulnerability affects all versions of Admin By Request (ABR). No specific version information is provided, so all installations of ABR are potentially impacted until updated.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The exploit probability (EPSS) is not available, but the flaw requires only a low-privileged user within ABR to submit crafted input, making it accessible and potentially highly impactful. The vulnerability is not listed in the CISA KEV catalog, but the persistence of root access after the session makes it a significant risk.

Generated by OpenCVE AI on August 26, 2026 at 08:21 UTC.

Remediation

Vendor Solution

Users and administrators of affected product versions are advised to update to the latest version promptly.


OpenCVE Recommended Actions

  • Apply the latest ABR update as soon as possible to remove the insecure input handling.
  • Review and restrict configuration changes that can modify the sudoers file, ensuring only authorized administrators can write to it.
  • Enforce stricter input validation and sanitization on all ABR logs or data entries that could influence system configuration files.
  • Audit the sudoers file for unexpected entries and establish monitoring to detect unauthorized modifications.

Generated by OpenCVE AI on August 26, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.
Title Insufficient input validation in Admin By Request (ABR)
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-26T14:01:01.835Z

Reserved: 2026-08-24T03:00:20.030Z

Link: CVE-2026-78237

cve-icon Vulnrichment

Updated: 2026-08-26T14:00:26.616Z

cve-icon NVD

Status : Received

Published: 2026-08-26T08:16:46.720

Modified: 2026-08-26T14:17:16.007

Link: CVE-2026-78237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T08:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation