CVE-2026-107510 PUBLISHED

Authenticated argument injection in NIOS command line leading to privilege escalation

Assigner: Infoblox
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Infoblox
Product NIOS
Versions Default: unaffected
  • affected from 9.0.x to 9.1.0 (incl.)

Credits

  • AUMLayer Cloud Labs LLP finder

References

Impacts

  • CAPEC-233 Privilege Escalation