CVE-2026-82457
HIGHDescription
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.
Is your site exposed to CVE-2026-82457?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-82457? +
How severe is CVE-2026-82457? +
How do I check if I'm vulnerable to CVE-2026-82457? +
Related Vulnerabilities
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP …
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through …
Microsoft ODBC Driver Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.