Junglewise Threat Intelligence

CVE-2026-68070: Authentication bypass with unauthenticated root command execution

CVE-2026-68070 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: <UNKNOWN>.

Executive brief

A critical function in the affected products lacks proper authentication controls, allowing unauthorized users to execute arbitrary system commands with root privileges. An attacker could exploit this to gain complete control over the affected system, potentially compromising data, disrupting operations, or using the device as a foothold for further attacks on connected infrastructure.

Technical details

This vulnerability is an authentication bypass combined with command injection. The affected products expose a critical function that fails to verify the caller's identity or authorization before processing user-supplied input. An attacker can pass arbitrary bytes directly to a system command without authentication, achieving remote code execution with root privileges. The attack requires network access to the exposed function but no prior authentication credentials. This results in complete system compromise and potential lateral movement within connected networks.

Affected products

  • <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References