Junglewise Threat Intelligence

CVE-2026-37525: Automotive Grade Linux afb-daemon privilege escalation in supervision Do command

CVE-2026-37525 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linuxfoundation Automotive Grade Linux. Vendors: Linuxfoundation, Automotive Grade Linux.

Executive brief

Automotive Grade Linux (AGL) uses a component called the app-framework-binder to manage communication between different automotive applications. A security flaw in this component allows a low-privileged local application to bypass security checks and execute commands with higher system privileges. This could allow an attacker to gain unauthorized control over sensitive vehicle functions or access restricted system data.

Technical details

A privilege escalation vulnerability exists in the afb-daemon component of Automotive Grade Linux (AGL) due to improper credential management in the supervision 'Do' command. The function 'on_supervision_call' in 'src/afb-supervision.c' explicitly nullifies request credentials by calling 'afb_context_change_cred' with a NULL value before dispatching an attacker-controlled API call. Because the attacker controls both the 'api' and 'verb' parameters via JSON input, they can invoke any registered API. If the target API relies on the credential context for authorization decisions, it may 'fail open' when encountering the NULL credentials, allowing a local low-privileged process to execute privileged operations.

Affected products

  • Automotive Grade Linux (AGL) app-framework-binder (afb-daemon) through v19.90.0

Timeline

  • 2018-02-14: other: Vulnerability introduced in commit abbb4599f0b921c6f434b6bd02bcfb277eecf745
  • 2026-04-30: disclosed: Initial disclosure by Innora Security Research
  • 2026-05-01: advisory: CVE published to NVD

References

Related threats