Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts. | |
| Title | su-exec through 0.3 Privilege Escalation via Numeric User ID | |
| Weaknesses | CWE-681 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:58.176Z
Reserved: 2026-08-29T13:23:00.303Z
Link: CVE-2026-82457
No data.
Status : Received
Published: 2026-08-29T14:16:38.910
Modified: 2026-08-29T14:16:38.910
Link: CVE-2026-82457
No data.
OpenCVE Enrichment
Updated: 2026-08-29T15:30:05Z