PT-2026-45557 · Steipete+1 · Codexbar

CVE-2026-49134

·

Published

2026-06-01

·

Updated

2026-07-22

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CodexBar versions prior to 0.32.0
Description A privilege escalation issue exists in the CLI installer. Local attackers can execute arbitrary commands as root by exploiting a race condition—a situation where the system's behavior depends on the sequence or timing of uncontrollable events—during temporary file handling. The installer uses mktemp to create a temporary file, writes a privileged shell payload into it, and executes it via bash with administrator privileges. A local process running under the same user can rewrite the installer body before the administrator prompt is approved, leading to the execution of attacker-controlled commands with root privileges.
Recommendations Update CodexBar to version 0.32.0 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49134

Affected Products

Codexbar