PT-2026-36503 · Agl · App-Framework-Binder

Sginnora

·

Published

2026-05-01

·

Updated

2026-05-07

·

CVE-2026-37525

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AGL app-framework-binder (afb-daemon) versions prior to 19.90.1
Description A privilege escalation issue exists in the supervision Do command. The on supervision call() function in src/afb-supervision.c nullifies request credentials by calling afb context change cred(&xreq->context, NULL) before dispatching an API call. Because the api and verb parameters are controlled via JSON input, an attacker can execute any registered API with a NULL credential context. If an API relies on context->credentials for authorization, it may fail open, allowing the attacker to gain elevated privileges.
Recommendations Update to a version later than 19.90.0.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-37525

Affected Products

App-Framework-Binder