CVE-2026-23648

HIGH

Glory RBG-100 ISPK-08 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these binaries to execute arbitrary commands with root privileges, enabling local privilege escalation.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
Glory Global Solutions/RBG-100
Published Feb 17, 2026
Tracked Since Feb 18, 2026