CVE-2026-82457

Published: Ago 29, 2026 Last Modified: Ago 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,5
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,8
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.

681

Incorrect Conversion between Numeric Types

Draft
Common Consequences
Security Scopes Affected:
Other Integrity
Potential Impacts:
Unexpected State Quality Degradation
Applicable Platforms
Languages: C, Not Language-Specific
View CWE Details
https://gist.github.com/thesmartshadow/ed96e2a88643c34a247c9b7cf9e311be
https://github.com/ncopa/su-exec
https://github.com/ncopa/su-exec/blob/89c016e6e08749d583efdeda04b9f73e1218e253/…
https://www.vulncheck.com/advisories/su-exec-through-0.3-privilege-escalation-v…