Junglewise Threat Intelligence

CVE-2026-32325: Fsas Technologies ServerView Agents privilege escalation via privilege chaining

CVE-2026-32325 · Severity: high · CVSS 7.8 · Published 2026-06-01

Executive brief

Fsas Technologies ServerView Agents, a server management tool, contains a vulnerability that allows a user with low-level access to escalate their permissions. If exploited, an attacker who has already gained access to the server can take full control of the system with administrative (SYSTEM) privileges. This could lead to complete data exposure, service disruption, or the installation of malicious software on the affected server.

Technical details

A privilege chaining vulnerability (CWE-268) exists in ServerView Agents for Windows versions V11.60.04 and earlier. The flaw allows a local authenticated user with low privileges to chain existing permissions or functionalities to gain SYSTEM-level access on the host operating system. The attack requires local access to the server but no user interaction. Fsas Technologies has released updates to address this issue, and users are advised to update to the latest version or apply recommended workarounds provided by the vendor.

Affected products

  • Fsas Technologies Inc. ServerView Agents for Windows V11.60.04 and earlier

Timeline

  • 2026-06-01: advisory: Advisory published by JPCERT/CC and Fsas Technologies
  • 2026-06-01: disclosed

References

Related threats