Executive brief
Nokia MantaRay NM, a network management solution, contains a security flaw that allows a local user with administrative rights to gain full root control over the underlying system. If exploited, an attacker could take complete command of the host, potentially leading to unauthorized data access, service disruption, or further network compromise. Organizations can temporarily reduce this risk by tightening sudo command restrictions for administrative accounts.
Technical details
A privilege escalation vulnerability exists in Nokia MantaRay NM due to insecure sudo configurations. A local attacker who already possesses administrative (local admin) privileges can exploit these permissions to bypass intended restrictions and gain full root access to the host operating system. This allows for complete filesystem access and the execution of arbitrary commands with the highest possible privileges. The vulnerability is addressed in version NM 25R1-NM and later; a temporary mitigation involves restricting the specific commands permitted via sudo for affected administrative accounts.
Affected products
- Nokia MantaRay NM < NM 25R1-NM
Timeline
- 2026-06-30: disclosed: Initial NVD publication date
- 2026-06-30: advisory: Nokia product security advisory published