EIP-2026-102940
PRE-CVEOracle Automated Service Manager 1.3 - Installation Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102940. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary This exploit demonstrates a local privilege escalation (LPE) vulnerability in Oracle Automated Service Manager 1.3.1 and SUNWswasr 4.3.1 due to insecure handling of temporary files in /tmp during installation. The exploit leverages a race condition to inject malicious cronjobs into root's crontab, allowing arbitrary command execution as root.
Description
Oracle Automated Service Manager 1.3 - Installation Privilege Escalation
Exploits (1)
This exploit demonstrates a local privilege escalation (LPE) vulnerability in Oracle Automated Service Manager 1.3.1 and SUNWswasr 4.3.1 due to insecure handling of temporary files in /tmp during installation. The exploit leverages a race condition to inject malicious cronjobs into root's crontab, allowing arbitrary command execution as root.