← Back to search

CVE-2026-91843

9.8 CRITICAL

Published 2026-09-16 · Updated 2026-09-18

AI risk analysis

Summary
The flaw is a stack overflow vulnerability during the unauthenticated login process, allowing attackers to execute arbitrary code with root privileges. This is critical because it provides a powerful attack vector for remote code execution without authentication.
Exploitability
Exploitation is relatively straightforward as it requires no user interaction and can be automated. The attacker must be able to send crafted input to the login process.
Blast radius
If exploited, the impact is severe as it allows attackers to gain full control over the system, potentially leading to data loss, system compromise, and further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of the affected software, as no specific version is mentioned in the description. Follow the vendor's security advisory for detailed instructions.
rceauth-bypassstack-overflowcriticalremote-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.