Vulnerability
Published 2026-10-01
Verified 2026-10-02

VxWorks 7 CVE-2026-104018 (CVSS 8.8): shell privilege check bypass → auth'd priv-esc; patch 26.09

Wind River CNA CVE-2026-104018 (published 1 October 2026; CVSS 3.1 8.8 High AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): improper privilege management (CWE-269) in the VxWorks 7 command shell when per-user command privileges are enforced. Under certain shell operations a command may run without the usual privilege check, so an authenticated low-privilege user can execute unauthorised commands — confidentiality/integrity/availability impact on the device. Affects all VxWorks 7 versions prior to 26.09; fixed in 26.09 (per Wind River CVE text). CISA SSVC on NVD: exploitation none / not automatable at publication. Primary: Wind River CVE page; NVD/Rapid7 amplify patch floor.

Product
Wind River VxWorks 7 (command shell with per-user privileges)
Versions
Affected: all VxWorks 7 prior to 26.09. Fixed: 26.09.
CVSS
(CVSS 3.1 High; Wind River)
Exploited in Australia?
unknown
Patch to
Upgrade VxWorks 7 to 26.09 or later. Until then: restrict shell access to trusted admins; review per-user command-privilege configs; segment OT/ICS management planes.

Primary: Wind River Support — CVE-2026-104018 VxWorks 7 privilege management · Vendor: Wind River Systems — CVE-2026-104018 (vendor primary) · CVE: CVE-2026-104018 · NVD — CVE-2026-104018 (CVSS 8.8; Wind River)

vulnerabilities ot ics network