CVE-2026-22069
Local Privilege Escalation in O+ Connect
Publication date: 2026-05-19
Last updated on: 2026-05-19
Assigner: OPPO Mobile Telecommunication Corp., Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a local privilege escalation issue in O+ Connect. It occurs because the software does not properly verify the identity of the caller on the pipe interface, allowing an attacker with limited privileges to potentially gain higher privileges.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could escalate their privileges on the affected system. This means they could gain higher-level access than intended, potentially leading to unauthorized actions such as modifying system settings, accessing sensitive data, or disrupting system availability.