Executive brief
A vulnerability in the Broadcom Automic Automation Agent for Unix systems allows a user with limited access to gain full administrative control over the host machine. This agent is used to automate and schedule tasks across enterprise environments; an exploit could allow an attacker to disrupt business operations, access sensitive data, or deploy malware with elevated privileges. Organizations using affected versions on Linux, AIX, or Solaris should update to the latest hotfix immediately.
Technical details
A vulnerability classified as 'Execution with Unnecessary Privileges' (CWE-250) exists in the Broadcom Automic Automation Agent Unix. The flaw allows a local attacker with low-level execution rights on the agent's executable to escalate their privileges to a higher level, potentially root, on the underlying operating system. The issue affects multiple Unix-based platforms including various distributions of Linux, AIX, and Solaris. The vulnerability is resolved in Automic Automation version 24.4.4 HF1 and version 26.0.0. Agents that display a Java Runtime Environment version message in their logs are reportedly unaffected.
Affected products
- Broadcom Automic Automation Agent Unix < 24.4.4 HF1
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched