CVE-2026-27668 PUBLISHED

Assigner: siemens
Reserved: 23.02.2026 Published: 14.04.2026 Updated: 14.04.2026

A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Siemens
Product RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
Versions Default: unknown
  • affected from 0 to V5.8 (excl.)

References

Problem Types

  • CWE-266: Incorrect Privilege Assignment CWE