CVE-2026-7270

HIGH

Local privilege escalation via execve()

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-7270. PoCs published by babyshen.

AI-analyzed exploit summary This repository contains a functional local privilege escalation exploit for CVE-2026-7270, targeting FreeBSD systems via an out-of-bounds memmove in `exec_args_adjust_args`. The exploit leverages a race condition with sshd to achieve root access.

Description

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

Exploits (1)

nomisec WORKING POC
by babyshen · poc
https://github.com/babyshen/freebsd-CVE-2026-7270

This repository contains a functional local privilege escalation exploit for CVE-2026-7270, targeting FreeBSD systems via an out-of-bounds memmove in `exec_args_adjust_args`. The exploit leverages a race condition with sshd to achieve root access.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: FreeBSD 11.0 through 14.4
No auth needed
Prerequisites: Local unprivileged shell · sshd running (default on FreeBSD)
devstral-2 · analyzed May 09, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-783
Status published
Products (8)
freebsd/freebsd 13.5 (14 CPE variants)
freebsd/freebsd 14.3 (12 CPE variants)
freebsd/freebsd 14.4 (4 CPE variants)
freebsd/freebsd 15.0 (7 CPE variants)
FreeBSD/FreeBSD 13.5-RELEASE - p13
FreeBSD/FreeBSD 14.3-RELEASE - p12
FreeBSD/FreeBSD 14.4-RELEASE - p3
FreeBSD/FreeBSD 15.0-RELEASE - p7
Published Apr 30, 2026
Tracked Since Apr 30, 2026