VxWorks 7 CVE-2026-104018 (CVSS 8.8): shell privilege check bypass → auth'd priv-esc; patch 26.09
Wind River CNA CVE-2026-104018 (published 1 October 2026; CVSS 3.1 8.8 High AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): improper privilege management (CWE-269) in the VxWorks 7 command shell when per-user command privileges are enforced. Under certain shell operations a command may run without the usual privilege check, so an authenticated low-privilege user can execute unauthorised commands — confidentiality/integrity/availability impact on the device. Affects all VxWorks 7 versions prior to 26.09; fixed in 26.09 (per Wind River CVE text). CISA SSVC on NVD: exploitation none / not automatable at publication. Primary: Wind River CVE page; NVD/Rapid7 amplify patch floor.
- Product
- Wind River VxWorks 7 (command shell with per-user privileges)
- Versions
- Affected: all VxWorks 7 prior to 26.09. Fixed: 26.09.
- CVSS
- (CVSS 3.1 High; Wind River)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade VxWorks 7 to 26.09 or later. Until then: restrict shell access to trusted admins; review per-user command-privilege configs; segment OT/ICS management planes.
Primary: Wind River Support — CVE-2026-104018 VxWorks 7 privilege management · Vendor: Wind River Systems — CVE-2026-104018 (vendor primary) · CVE: CVE-2026-104018 · NVD — CVE-2026-104018 (CVSS 8.8; Wind River)
