CVE-2026-0873

MEDIUM

Ercom Cryptobox >=v4.40.x - Authenticated Privilege Escalation to Global Administrator

Title source: llm
STIX 2.1

Description

On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with knowledge to elevate his account to global administrator.

References (1)

Core 1
Core References

Scores

CVSS v4 4.8
EPSS 0.0024
EPSS Percentile 14.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:U

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1220 CWE-79
Status published
Products (1)
Ercom/Cryptobox v4.40.x
Published Feb 04, 2026
Tracked Since Feb 18, 2026