CVE-2026-27668

HIGH

Siemens RUGGEDCOM CROSSBOW SAM-P <V5.8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
Siemens/RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) < V5.8
Published Apr 14, 2026
Tracked Since Apr 14, 2026